Vulnerabilities
Vulnerable Software
Grafana:  Security Vulnerabilities
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
CVSS Score
5.4
EPSS Score
0.002
Published
2020-05-24
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVSS Score
6.1
EPSS Score
0.003
Published
2020-05-24
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
CVSS Score
5.5
EPSS Score
0.001
Published
2020-04-29
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-04-29
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVSS Score
6.1
EPSS Score
0.011
Published
2020-04-27
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
CVSS Score
6.1
EPSS Score
0.024
Published
2020-04-24
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.
CVSS Score
4.9
EPSS Score
0.002
Published
2019-09-23
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
CVSS Score
7.5
EPSS Score
0.908
Published
2019-09-03
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
CVSS Score
5.4
EPSS Score
0.082
Published
2019-06-30
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.
CVSS Score
6.1
EPSS Score
0.006
Published
2019-02-06


Contact Us

Shodan ® - All rights reserved