Grafana
grafana
125 CVEs • 17 products
Products (17)
Click to collapseToggle
Products (17)
Click to collapse
CVEs (125)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to ad...Show more |
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access. |
2Grafana Netapp2E Series Performance Analyzer GrafanaJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. |
4Fedoraproject GrafanaRedhat+1 more6Enterprise Linux FedoraGrafana+3 moreJun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system av...Show more |
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. |
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. |
2Grafana Netapp2E Series Performance Analyzer GrafanaJun 17, 2026 Jul 27, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard af...Show more |
4Fedoraproject GrafanaNetapp+1 more5Backports Sle E Series Performance AnalyzerFedora+2 moreJun 17, 2026 Jun 3, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result...Show more |
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. |
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. |
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. |
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. |
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option. |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Apr 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable. |
3Fedoraproject GrafanaRedhat4Ceph Storage Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive inform...Show more |
Grafana version < 6.7.3 is vulnerable for annotation popup XSS. |
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. |
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a...Show more |
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. |
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). |