Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grafana HIGH 7.5
CVE-2022-39201

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Gr…

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Grafana HIGH 7.5
CVE-2022-31130

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authe…

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Grafana HIGH 7.8
CVE-2022-31123

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin …

Fix: 8.5.14 / 9.1.8+
Fix from $1,950 2022-10-13
Grafana MEDIUM 6.6
CVE-2022-35957

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to…

Fix: 8.5.13 / 9.0.9+
Fix from $1,600 2022-09-20
Grafana Image Renderer HIGH 8.1
CVE-2022-31176

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). …

Fix: 3.6.1+
Fix from $1,950 2022-09-02
Grafana HIGH 7.5
CVE-2022-31107

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a mal…

Fix: 8.3.10 / 8.4.10+
Fix from $1,950 2022-07-15
Grafana HIGH 8.7
CVE-2022-31097EPSS 69%

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are…

Fix: 8.3.10 / 8.4.10+
Fix from $1,950 2022-07-15
Grafana HIGH 7.5
CVE-2022-32276

Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vu…

No fix yet
Fix from $1,950 2022-06-17
Grafana HIGH 7.5
CVE-2022-32275EPSS 9%

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd …

No fix yet
Fix from $1,950 2022-06-06
Grafana HIGH 8.5
CVE-2022-29170

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to config…

Fix: 7.5.16 / 8.5.3+
Fix from $1,950 2022-05-20
Grafana CRITICAL 9.8
CVE-2022-28660

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…

Fix: 1.2.1+
Fix from $2,300 2022-05-20
Grafana HIGH 8.8
CVE-2022-24812

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to…

Fix: 8.4.6+
Fix from $1,950 2022-04-12
Grafana CRITICAL 9.8
CVE-2022-26148EPSS 53%

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source co…

Fix: after 7.3.4
Fix from $2,300 2022-03-21
Grafana HIGH 8.8
CVE-2022-21703

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…

Fix: 3.0 / 7.5.15+
Fix from $1,950 2022-02-08
Grafana MEDIUM 5.4
CVE-2022-21702

Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datas…

Fix: 3.0 / 7.5.15+
Fix from $1,600 2022-02-08
Agent HIGH 7.5
CVE-2021-41090

Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.…

Fix: 0.20.1 / 0.21.2+
Fix from $1,950 2021-12-08
Grafana HIGH 7.5
CVE-2021-43798 KEVEPSS 89%

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vul…

Fix: 8.0.7 / 8.1.8+
Fix from $1,950 2021-12-07
Grafana HIGH 7.2
CVE-2021-41244

Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enable…

Fix: 8.2.4+
Fix from $1,950 2021-11-15
Grafana MEDIUM 6.1
CVE-2021-41174EPSS 85%

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL …

Fix: 8.2.3+
Fix from $1,600 2021-11-03
Grafana HIGH 7.3
CVE-2021-39226 KEVEPSS 100%

Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…

Fix: 7.5.11 / 8.1.6+
Fix from $1,950 2021-10-05
Loki MEDIUM 5.3
CVE-2021-36156

An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted…

Fix: after 2.2.1
Fix from $1,600 2021-08-03
Enterprise Metrics MEDIUM 5.5
CVE-2021-31231

The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.…

Fix: 1.2.1+
Fix from $1,600 2021-04-30
Grafana HIGH 7.5
CVE-2021-28148

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without …

Fix: 6.7.6 / 7.3.10+
Fix from $1,950 2021-03-22
Grafana MEDIUM 6.5
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Gr…

Fix: 6.7.6 / 7.3.10+
Fix from $1,600 2021-03-22
Grafana HIGH 7.1
CVE-2021-27962

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data sour…

Fix: 7.3.10 / 7.4.5+
Fix from $1,950 2021-03-22
Grafana MEDIUM 6.5
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authent…

Fix: 7.4.5+
Fix from $1,600 2021-03-22
Grafana HIGH 7.5
CVE-2021-27358EPSS 83%

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API cal…

Fix: after 7.4.1
Fix from $1,950 2021-03-18
Grafana CRITICAL 9.8
CVE-2020-27846

A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…

Fix: 0.4.3 / 6.7.5+
Fix from $2,300 2020-12-21
Grafana MEDIUM 6.1
CVE-2020-24303

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

Fix: after 7.0.5
Fix from $1,600 2020-10-28
Grafana MEDIUM 6.5
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the da…

Fix: after 6.4.3
Fix from $1,600 2020-08-28