Vulnerabilities > Grafana > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-11-15 | CVE-2021-41244 | Incorrect Authorization vulnerability in Grafana Grafana is an open-source platform for monitoring and observability. | 6.5 |
2021-11-03 | CVE-2021-41174 | Cross-site Scripting vulnerability in Grafana Grafana is an open-source platform for monitoring and observability. | 4.3 |
2021-08-03 | CVE-2021-36156 | Path Traversal vulnerability in Grafana Loki An issue was discovered in Grafana Loki through 2.2.1. | 5.0 |
2021-04-30 | CVE-2021-31231 | Unspecified vulnerability in Grafana Enterprise Metrics The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. | 5.5 |
2021-03-22 | CVE-2021-28148 | Missing Authentication for Critical Function vulnerability in Grafana One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. | 5.0 |
2021-03-22 | CVE-2021-28146 | Incorrect Authorization vulnerability in Grafana The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. | 4.0 |
2021-03-22 | CVE-2021-27962 | Unspecified vulnerability in Grafana Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access. network grafana | 4.9 |
2021-03-18 | CVE-2021-27358 | The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. | 5.0 |
2020-10-28 | CVE-2020-24303 | Cross-site Scripting vulnerability in Grafana Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. | 4.3 |
2020-08-28 | CVE-2019-19499 | SQL Injection vulnerability in Grafana Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | 4.0 |