Vulnerabilities > Grafana
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-10-28 | CVE-2020-24303 | Cross-site Scripting vulnerability in Grafana Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. | 4.3 |
2020-08-28 | CVE-2019-19499 | SQL Injection vulnerability in Grafana Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | 4.0 |
2020-07-27 | CVE-2020-11110 | Cross-site Scripting vulnerability in multiple products Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. | 5.4 |
2020-06-03 | CVE-2020-13379 | Server-Side Request Forgery (SSRF) vulnerability in multiple products The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. | 8.2 |
2020-06-02 | CVE-2018-18625 | Cross-site Scripting vulnerability in Grafana 5.3.1 Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. | 4.3 |
2020-06-02 | CVE-2018-18624 | Cross-site Scripting vulnerability in Grafana 5.3.1 Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. | 4.3 |
2020-06-02 | CVE-2018-18623 | Cross-site Scripting vulnerability in Grafana 5.3.1 Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. | 4.3 |
2020-05-24 | CVE-2020-13430 | Cross-site Scripting vulnerability in Grafana Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | 6.1 |
2020-05-24 | CVE-2020-13429 | Cross-site Scripting vulnerability in Grafana Piechart-Panel legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option. | 3.5 |
2020-04-29 | CVE-2020-12459 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable. | 5.5 |