Vulnerabilities > Grafana > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-27 CVE-2020-11110 Cross-site Scripting vulnerability in multiple products
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
network
low complexity
grafana netapp CWE-79
5.4
2020-06-02 CVE-2018-18625 Cross-site Scripting vulnerability in Grafana 5.3.1
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen.
network
grafana CWE-79
4.3
2020-06-02 CVE-2018-18624 Cross-site Scripting vulnerability in Grafana 5.3.1
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen.
network
grafana CWE-79
4.3
2020-06-02 CVE-2018-18623 Cross-site Scripting vulnerability in Grafana 5.3.1
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen.
network
grafana CWE-79
4.3
2020-05-24 CVE-2020-13430 Cross-site Scripting vulnerability in Grafana
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
network
low complexity
grafana CWE-79
6.1
2020-04-29 CVE-2020-12459 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
local
low complexity
grafana fedoraproject CWE-732
5.5
2020-04-29 CVE-2020-12458 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
An information-disclosure flaw was found in Grafana through 6.7.3.
local
low complexity
grafana redhat fedoraproject CWE-732
5.5
2020-04-27 CVE-2020-12052 Cross-site Scripting vulnerability in Grafana
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
network
grafana CWE-79
4.3
2020-04-24 CVE-2020-12245 Cross-site Scripting vulnerability in Grafana
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
network
grafana CWE-79
4.3
2019-09-23 CVE-2019-15635 Insufficiently Protected Credentials vulnerability in Grafana 5.4.0
An issue was discovered in Grafana 5.4.0.
network
low complexity
grafana CWE-522
4.0