Skip to main content

Vendor archive

grafana CVEs

Beta · best-effort

125 CVEs tagged to vendor grafana13 Critical, 36 High, 71 Medium, 5 Low, 0 Unrated.

CVE-2023-3010

Published Oct 25, 2023

Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4399

Published Oct 17, 2023

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so t…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4457

Published Oct 16, 2023

Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information di…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4822

Published Oct 16, 2023

Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Ad…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3128

Published Jun 22, 2023

Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2801

Published Jun 6, 2023

Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such que…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2183

Published Jun 6, 2023

Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1387

Published Apr 26, 2023

Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1410

Published Mar 23, 2023

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnera…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22462

Published Mar 2, 2023

Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerabil…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0594

Published Mar 1, 2023

Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0507

Published Mar 1, 2023

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23498

Published Feb 3, 2023

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39324

Published Jan 27, 2023

Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalU…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23552

Published Jan 27, 2023

Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnera…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-44643

Published Dec 20, 2022

A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label sele…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46156

Published Nov 30, 2022

The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39307

Published Nov 9, 2022

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39306

Published Nov 9, 2022

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39328

Published Nov 8, 2022

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares lo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-39229

Published Oct 13, 2022

Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by reg…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39201

Published Oct 13, 2022

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31130

Published Oct 13, 2022

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some desti…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36062

Published Sep 22, 2022

Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resu…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 125 CVEsPage 3 of 5