← Back

Grafana

grafana

Vendor: Grafana • 103 CVEs

CVEs (103)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Grafana
NetappRedhat
7Active Iq Performance Analytics Services
Ceph StorageEnterprise Linux Desktop+4 more
Nov 21, 2024
Dec 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
2Grafana
Redhat
2Ceph Storage
Grafana
Nov 21, 2024
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
2Grafana
Netapp
3Active Iq Performance Analytics Services
GrafanaStoragegrid Webscale Nas Bridge
Nov 21, 2024
Jun 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.