Vulnerabilities > Grafana

DATE CVE VULNERABILITY TITLE RISK
2021-12-08 CVE-2021-41090 Cleartext Storage of Sensitive Information vulnerability in Grafana Agent
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack.
network
grafana CWE-312
4.3
2021-12-07 CVE-2021-43798 Path Traversal vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-22
5.0
2021-11-15 CVE-2021-41244 Incorrect Authorization vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-863
6.5
2021-11-03 CVE-2021-41174 Cross-site Scripting vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
grafana CWE-79
4.3
2021-10-05 CVE-2021-39226 Improper Authentication vulnerability in multiple products
Grafana is an open source data visualization platform.
network
low complexity
grafana fedoraproject CWE-287
7.3
2021-08-03 CVE-2021-36156 Path Traversal vulnerability in Grafana Loki
An issue was discovered in Grafana Loki through 2.2.1.
network
low complexity
grafana CWE-22
5.0
2021-04-30 CVE-2021-31231 Unspecified vulnerability in Grafana Enterprise Metrics
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used.
local
low complexity
grafana
5.5
2021-03-22 CVE-2021-28148 Missing Authentication for Critical Function vulnerability in Grafana
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication.
network
low complexity
grafana CWE-306
5.0
2021-03-22 CVE-2021-28147 Unspecified vulnerability in Grafana
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue.
network
grafana
3.5
2021-03-22 CVE-2021-28146 Incorrect Authorization vulnerability in Grafana
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue.
network
low complexity
grafana CWE-863
4.0