Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Grafana MEDIUM 5.4
CVE-2020-11110EPSS 10%

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript …

Fix: after 6.7.1
Fix from $1,600 2020-07-27
Grafana HIGH 8.2
CVE-2020-13379EPSS 100%

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clie…

Fix: after 7.0.1
Fix from $1,950 2020-06-03
Grafana MEDIUM 6.1
CVE-2018-18623

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

Patch available
Fix from $1,600 2020-06-02
Grafana MEDIUM 6.1
CVE-2018-18624

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-1…

Patch available
Fix from $1,600 2020-06-02
Grafana MEDIUM 6.1
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-…

Patch available
Fix from $1,600 2020-06-02
Grafana MEDIUM 6.1
CVE-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

Fix: 7.0.0+
Fix from $1,600 2020-05-24
Piechart Panel MEDIUM 5.4
CVE-2020-13429

legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.

Fix: 1.5.0+
Fix from $1,600 2020-05-24
Grafana MEDIUM 5.5
CVE-2020-12458

An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana…

Fix: after 6.7.3
Fix from $1,600 2020-04-29
Grafana MEDIUM 5.5
CVE-2020-12459

In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain…

Fix: after 6.3.6
Fix from $1,600 2020-04-29
Grafana MEDIUM 6.1
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

Fix: 6.7.3+
Fix from $1,600 2020-04-27
Grafana MEDIUM 6.1
CVE-2020-12245

Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

Fix: 6.7.3+
Fix from $1,600 2020-04-24
Grafana HIGH 7.5
CVE-2019-15043EPSS 63%

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack ag…

Fix: 5.4.5 / 6.3.4+
Fix from $1,950 2019-09-03
Grafana MEDIUM 5.4
CVE-2019-13068EPSS 52%

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

Fix: 6.2.5+
Fix from $1,600 2019-06-30
Piechart Panel MEDIUM 6.1
CVE-2015-9282

The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana…

Fix: after 1.3.4
Fix from $1,600 2019-02-06
Grafana MEDIUM 5.4
CVE-2018-1000816

Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can resu…

No fix yet
Fix from $1,600 2018-12-20
Grafana MEDIUM 6.5
CVE-2018-19039EPSS 7%

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

Fix: 4.6.5 / 5.3.3+
Fix from $1,600 2018-12-13
Grafana CRITICAL 9.8
CVE-2018-15727EPSS 64%

Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cooki…

Fix: 4.6.4 / 5.2.3+
Fix from $2,300 2018-08-29
Grafana MEDIUM 6.1
CVE-2018-12099

Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

Fix: after 5.1.3
Fix from $1,600 2018-06-11