<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Grafana (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/grafana.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/grafana-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Grafana (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-27876 – A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27876</guid>
    <pubDate>Fri, 27 Mar 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27876</strong></p>
  <p>A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path.  Only instances with the sqlExpressions feature toggle enabled are vulnerable.  Only instances in the following version ranges ar…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28377 – A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28377</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28377</strong></p>
  <p>A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.  Thanks to william_goodfellow for reporting this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32117 – The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32117</guid>
    <pubDate>Wed, 11 Mar 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32117</strong></p>
  <p>The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the link to a javascript: URI; when any Viewer drag-zooms on the panel, the payload executes in the Grafana…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21720 – Every uncached /avatar/:hash request spawns a goroutine that refreshes the Grava...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21720</guid>
    <pubDate>Tue, 27 Jan 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21720</strong></p>
  <p>Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22643 – In Grafana, an excessively long dashboard title or panel name will cause Chromiu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22643</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22643</strong></p>
  <p>In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22638 – A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22638</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22638</strong></p>
  <p>A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is ins…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0713 – A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0713</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0713</strong></p>
  <p>A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dash…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0712 – An open redirect vulnerability has been identified in Grafana OSS that can be ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0712</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0712</strong></p>
  <p>An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41115 – SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in Apri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41115</guid>
    <pubDate>Fri, 21 Nov 2025 15:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41115</strong></p>
  <p>SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management.  In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric ex…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11539 – Grafana Image Renderer is vulnerable to remote code execution due to an arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11539</guid>
    <pubDate>Thu, 09 Oct 2025 08:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11539</strong></p>
  <p>Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then loaded by the Chromium process.  Instances are vulnerable if:  1. The default token ("authToken") is not c…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-58746 – The Volkov Labs Business Links panel for Grafana provides an interface to naviga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58746</guid>
    <pubDate>Mon, 08 Sep 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-58746</strong></p>
  <p>The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6023 – An open redirect vulnerability has been identified in Grafana OSS that can be ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6023</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6023</strong></p>
  <p>An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0.  The open redirect can be chained with path traversal vulnerabilities to achieve XSS.  Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3260 – A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3260</guid>
    <pubDate>Mon, 02 Jun 2025 10:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3260</strong></p>
  <p>A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1).  Impact:  - Viewers can view all dashboards/folders regardless of permissions  - Editors can view/edit/delete all dashboards/folders regardless of permissions  - Editors can create…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4123 – A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4123</guid>
    <pubDate>Thu, 22 May 2025 08:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4123</strong></p>
  <p>A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is ins…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-9264 – The SQL Expressions experimental feature of Grafana allows for the evaluation of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9264</guid>
    <pubDate>Fri, 18 Oct 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-9264</strong></p>
  <p>The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack.  The `duckdb` binary must be present in Grafana'…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8996 – Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8996</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8996</strong></p>
  <p>Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8975 – Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8975</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8975</strong></p>
  <p>Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8986 – The grafana plugin SDK bundles build metadata into the binaries it compiles; thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8986</guid>
    <pubDate>Thu, 19 Sep 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8986</strong></p>
  <p>The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`.   If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5526 – Grafana OnCall is an easy-to-use on-call management tool that will help reduce t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5526</guid>
    <pubDate>Wed, 05 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5526</strong></p>
  <p>Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers.  Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vulnerability in the webhook functionallity.   This issue was fixed in version 1.5.2</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31634 – In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31634</guid>
    <pubDate>Wed, 27 Mar 2024 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31634</strong></p>
  <p>In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the default username and password can be used to enter the Grafana management console without logging in, a related issue to CVE-…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5123 – The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-js...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5123</guid>
    <pubDate>Wed, 14 Feb 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5123</strong></p>
  <p>The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of the dashboard-supplied path parameter, it was possible to include path traversal…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36649 – Insertion of sensitive information in the centralized (Grafana) logging system i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36649</guid>
    <pubDate>Tue, 12 Dec 2023 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36649</strong></p>
  <p>Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3010 – Grafana is an open-source platform for monitoring and observability. 

The World...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3010</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3010</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-3128 – Grafana is validating Azure AD accounts based on the email claim. 

On Azure AD,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3128</guid>
    <pubDate>Thu, 22 Jun 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-3128</strong></p>
  <p>Grafana is validating Azure AD accounts based on the email claim.   On Azure AD, the profile email field is not unique and can be easily modified.   This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2801 – Grafana is an open-source platform for monitoring and observability. 

Using pub...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2801</guid>
    <pubDate>Tue, 06 Jun 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2801</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance.  The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly.  This might enabl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-820</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-24831 – Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24831</guid>
    <pubDate>Mon, 17 Apr 2023 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-24831</strong></p>
  <p>Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3.  Attackers could login without authorization. This is fixed in 0.13.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0594 – Grafana is an open-source platform for monitoring and observability. 

Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0594</guid>
    <pubDate>Wed, 01 Mar 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0594</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization.   The stored XSS vulnerability was possible due the value of a span's attributes/resources were not properly sanitized and this will be rendered when the span's attributes/resources are expanded.  An attacker needs to have the…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0507 – Grafana is an open-source platform for monitoring and observability. 

Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0507</guid>
    <pubDate>Wed, 01 Mar 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0507</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.   The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.   An atta…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23498 – Grafana is an open-source platform for monitoring and observability. When dataso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23498</guid>
    <pubDate>Fri, 03 Feb 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23498</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patche…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23552 – Grafana is an open-source platform for monitoring and observability. Starting wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23552</guid>
    <pubDate>Fri, 27 Jan 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23552</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized u…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46156 – The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46156</guid>
    <pubDate>Wed, 30 Nov 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46156</strong></p>
  <p>The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The authentication token used to communicate with the Synthetic Monitoring API is exposed through a debugging endpoint. This to…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39328 – Grafana is an open-source platform for monitoring and observability. Versions st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39328</guid>
    <pubDate>Tue, 08 Nov 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39328</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36062 – Grafana is an open-source platform for monitoring and observability. In versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36062</guid>
    <pubDate>Thu, 22 Sep 2022 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36062</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating l…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38370 – Apache IoTDB grafana-connector version 0.13.0 contains an interface without auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38370</guid>
    <pubDate>Mon, 05 Sep 2022 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38370</strong></p>
  <p>Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31176 – Grafana Image Renderer is a Grafana backend plugin that handles rendering of pan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31176</guid>
    <pubDate>Fri, 02 Sep 2022 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31176</strong></p>
  <p>Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana)…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31107 – Grafana is an open-source platform for monitoring and observability. In versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31107</guid>
    <pubDate>Fri, 15 Jul 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31107</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31097 – Grafana is an open-source platform for monitoring and observability. Versions on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31097</guid>
    <pubDate>Fri, 15 Jul 2022 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31097</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32276 – Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snaps...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32276</guid>
    <pubDate>Fri, 17 Jun 2022 13:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32276</strong></p>
  <p>Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32275 – Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32275</guid>
    <pubDate>Mon, 06 Jun 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32275</strong></p>
  <p>Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28660 – The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28660</guid>
    <pubDate>Fri, 20 May 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28660</strong></p>
  <p>The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24812 – Grafana is an open-source platform for monitoring and observability. When fine-g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24812</guid>
    <pubDate>Tue, 12 Apr 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24812</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent requests with any API Key evaluate to the same permissions as the previous requests.…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26148 – An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26148</guid>
    <pubDate>Mon, 21 Mar 2022 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26148</strong></p>
  <p>An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23126 – TeslaMate before 1.25.1 (when using the default Docker configuration) allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23126</guid>
    <pubDate>Mon, 24 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23126</strong></p>
  <p>TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43798 – Grafana is an open-source platform for monitoring and observability. Grafana ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43798</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43798</guid>
    <pubDate>Tue, 07 Dec 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43798</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upg…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43798">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41244 – Grafana is an open-source platform for monitoring and observability. In affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41244</guid>
    <pubDate>Mon, 15 Nov 2021 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41244</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations. Grafana 8.0 introduced a mechanism which allowed users with the Organization Admin role to list, add, remove, and update users…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-39226 – Grafana is an open source data visualization platform. In affected versions unau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39226</guid>
    <pubDate>Tue, 05 Oct 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-39226</strong></p>
  <p>Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapsho…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-27437 – The affected product allows attackers to obtain sensitive information from the W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27437</guid>
    <pubDate>Fri, 07 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-27437</strong></p>
  <p>The affected product allows attackers to obtain sensitive information from the WISE-PaaS dashboard. The system contains a hard-coded administrator username and password that can be used to query Grafana APIs. Authentication is not required for exploitation on the WISE-PaaS/RMM (versions prior to 9.0.1).</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28148 – One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28148</guid>
    <pubDate>Mon, 22 Mar 2021 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28148</strong></p>
  <p>One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27962 – Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27962</guid>
    <pubDate>Mon, 22 Mar 2021 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27962</strong></p>
  <p>Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27358 – The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27358</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27358</guid>
    <pubDate>Thu, 18 Mar 2021 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27358</strong></p>
  <p>The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27358">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13379 – The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13379</guid>
    <pubDate>Wed, 03 Jun 2020 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13379</strong></p>
  <p>The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana v…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15043 – In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15043</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15043</guid>
    <pubDate>Tue, 03 Sep 2019 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15043</strong></p>
  <p>In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15043">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-15727 – Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authenticatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15727</guid>
    <pubDate>Wed, 29 Aug 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-15727</strong></p>
  <p>Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15727">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
