Vulnerabilities
Vulnerable Software
Grafana:  >> Grafana  >> 5.4.0  Security Vulnerabilities
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVSS Score
6.1
EPSS Score
0.007
Published
2020-04-27
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVSS Score
6.1
EPSS Score
0.032
Published
2020-04-24
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.
CVSS Score
4.9
EPSS Score
0.001
Published
2019-09-23
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CVSS Score
7.5
EPSS Score
0.909
Published
2019-09-03
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
CVSS Score
5.4
EPSS Score
0.05
Published
2019-06-30


Contact Us

Shodan ® - All rights reserved