Vulnerabilities > Grafana > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-04-30 | CVE-2021-31231 | Unspecified vulnerability in Grafana Enterprise Metrics The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. | 5.5 |
2021-03-22 | CVE-2021-28147 | Unspecified vulnerability in Grafana The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. | 6.5 |
2021-03-22 | CVE-2021-28146 | Incorrect Authorization vulnerability in Grafana The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. | 6.5 |
2020-10-28 | CVE-2020-24303 | Cross-site Scripting vulnerability in Grafana Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. | 6.1 |
2020-08-28 | CVE-2019-19499 | SQL Injection vulnerability in Grafana Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | 6.5 |
2020-07-27 | CVE-2020-11110 | Cross-site Scripting vulnerability in multiple products Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. | 5.4 |
2020-06-02 | CVE-2018-18625 | Cross-site Scripting vulnerability in Grafana 5.3.1 Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. | 6.1 |
2020-06-02 | CVE-2018-18624 | Cross-site Scripting vulnerability in Grafana 5.3.1 Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. | 6.1 |
2020-06-02 | CVE-2018-18623 | Cross-site Scripting vulnerability in Grafana 5.3.1 Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. | 6.1 |
2020-05-24 | CVE-2020-13430 | Cross-site Scripting vulnerability in Grafana Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | 6.1 |