Vulnerabilities
Vulnerable Software
Grafana:  >> Grafana  >> 3.0.0  Security Vulnerabilities
CVE-2021-39226
Known exploited
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.
CVSS Score
9.8
EPSS Score
0.944
Published
2021-10-05
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS Score
9.8
EPSS Score
0.121
Published
2020-12-21
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
CVSS Score
6.1
EPSS Score
0.013
Published
2020-10-28
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
CVSS Score
6.5
EPSS Score
0.374
Published
2020-08-28
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
CVSS Score
5.4
EPSS Score
0.676
Published
2020-07-27
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVSS Score
6.1
EPSS Score
0.003
Published
2020-05-24
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
CVSS Score
5.5
EPSS Score
0.001
Published
2020-04-29
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVSS Score
6.1
EPSS Score
0.012
Published
2020-04-27
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVSS Score
6.1
EPSS Score
0.032
Published
2020-04-24
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CVSS Score
7.5
EPSS Score
0.887
Published
2019-09-03


Contact Us

Shodan ® - All rights reserved