Grafana
grafana
125 CVEs • 17 products
Products (17)
Click to collapseToggle
Products (17)
Click to collapse
CVEs (125)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote u...Show more |
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear...Show more |
3Grafana NetappRedhat7Active Iq Performance Analytics Services Ceph StorageEnterprise Linux Desktop+4 moreNov 21, 2024 Dec 13, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. |
2Grafana Redhat2Ceph Storage GrafanaNov 21, 2024 Aug 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user. |
2Grafana Netapp3Active Iq Performance Analytics Services GrafanaStoragegrid Webscale Nas BridgeNov 21, 2024 Jun 11, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. |