Vulnerabilities > Grafana

DATE CVE VULNERABILITY TITLE RISK
2021-10-05 CVE-2021-39226 Improper Authentication vulnerability in Grafana
Grafana is an open source data visualization platform.
network
grafana CWE-287
6.8
2021-08-03 CVE-2021-36156 Path Traversal vulnerability in Grafana Loki
An issue was discovered in Grafana Loki through 2.2.1.
network
low complexity
grafana CWE-22
5.0
2021-04-30 CVE-2021-31231 Improper Input Validation vulnerability in Grafana Enterprise Metrics
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used.
local
low complexity
grafana CWE-20
2.1
2021-03-22 CVE-2021-28148 Improper Authentication vulnerability in Grafana
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication.
network
low complexity
grafana CWE-287
5.0
2021-03-22 CVE-2021-28147 Unspecified vulnerability in Grafana
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue.
network
grafana
3.5
2021-03-22 CVE-2021-28146 Incorrect Authorization vulnerability in Grafana
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue.
network
low complexity
grafana CWE-863
4.0
2021-03-22 CVE-2021-27962 Incorrect Permission Assignment for Critical Resource vulnerability in Grafana
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
network
grafana CWE-732
4.9
2021-03-18 CVE-2021-27358 Unspecified vulnerability in Grafana
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.
network
low complexity
grafana
5.0
2020-12-21 CVE-2020-27846 Misinterpretation of Input vulnerability in multiple products
A signature verification vulnerability exists in crewjam/saml.
network
low complexity
grafana saml-project redhat fedoraproject CWE-115
critical
10.0
2020-10-28 CVE-2020-24303 Cross-site Scripting vulnerability in Grafana
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
network
grafana CWE-79
4.3