Vulnerabilities
Vulnerable Software
Grafana:  Security Vulnerabilities
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
CVSS Score
7.5
EPSS Score
0.83
Published
2021-03-18
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Score
9.8
EPSS Score
0.046
Published
2020-12-21
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
CVSS Score
6.1
EPSS Score
0.018
Published
2020-10-28
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
CVSS Score
6.5
EPSS Score
0.036
Published
2020-08-28
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
CVSS Score
5.4
EPSS Score
0.092
Published
2020-07-27
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
CVSS Score
8.2
EPSS Score
0.999
Published
2020-06-03
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVSS Score
6.1
EPSS Score
0.018
Published
2020-06-02
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVSS Score
6.1
EPSS Score
0.014
Published
2020-06-02
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVSS Score
6.1
EPSS Score
0.012
Published
2020-06-02
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
CVSS Score
5.4
EPSS Score
0.007
Published
2020-05-24


Contact Us

Shodan ® - All rights reserved