<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Grafana</title>
  <link>https://cvedaily.com/pages/tags/grafana.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/grafana.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Grafana</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-33380 – A vulnerability in SQL Expressions allows an authenticated attacker to read arbi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33380</guid>
    <pubDate>Wed, 13 May 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33380</strong></p>
  <p>A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28383 – A request to the Grafana plugin resources endpoint can cause unbounded memory al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28383</guid>
    <pubDate>Wed, 13 May 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28383</strong></p>
  <p>A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28379 – A race condition in Grafana Live allows authenticated users with Viewer role to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28379</guid>
    <pubDate>Wed, 13 May 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28379</strong></p>
  <p>A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28376 – The Grafana Live push endpoint can be exploited to cause unbounded memory alloca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28376</guid>
    <pubDate>Wed, 13 May 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28376</strong></p>
  <p>The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-21727 – ---
title: Cross-Tenant Legacy Correlation Disclosure and Deletion
draft: false
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21727</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-21727</strong></p>
  <p>--- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero:   image: /static/img/heros/hero-legal2.svg   content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion" date: 2026-01-29 product: Grafana severity: Low cve: CVE-2026-21727 cvss_score: "3.3" cvss_vector: "CVSS:3.3/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N" fixed_versions:   - ">=11.6.11 >=12.0.9 >=12.1.6 >=12…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12141 – In Grafana's alerting system, users with edit permissions for a contact point, s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12141</guid>
    <pubDate>Wed, 15 Apr 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12141</strong></p>
  <p>In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the tes…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28375 – A testdata data-source can be used to trigger out-of-memory crashes in Grafana.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28375</guid>
    <pubDate>Fri, 27 Mar 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28375</strong></p>
  <p>A testdata data-source can be used to trigger out-of-memory crashes in Grafana.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27879 – A resample query can be used to trigger out-of-memory crashes in Grafana.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27879</guid>
    <pubDate>Fri, 27 Mar 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27879</strong></p>
  <p>A resample query can be used to trigger out-of-memory crashes in Grafana.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27876 – A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27876</guid>
    <pubDate>Fri, 27 Mar 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27876</strong></p>
  <p>A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path.  Only instances with the sqlExpressions feature toggle enabled are vulnerable.  Only instances in the following version ranges ar…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28377 – A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28377</guid>
    <pubDate>Thu, 26 Mar 2026 22:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28377</strong></p>
  <p>A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3.  Thanks to william_goodfellow for reporting this vulnerability.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33375 – The Grafana MSSQL data source plugin contains a logic flaw that allows a low-pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33375</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33375</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33375</strong></p>
  <p>The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33375">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21724 – A vulnerability has been discovered in Grafana OSS where an authorization bypass...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21724</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21724</strong></p>
  <p>A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21724">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32117 – The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32117</guid>
    <pubDate>Wed, 11 Mar 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32117</strong></p>
  <p>The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the link to a javascript: URI; when any Viewer drag-zooms on the panel, the payload executes in the Grafana…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-21725 – A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21725</guid>
    <pubDate>Wed, 25 Feb 2026 13:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-21725</strong></p>
  <p>A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so.  This requires several very stringent conditions to be met:  - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the s…</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41117 – Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41117</guid>
    <pubDate>Thu, 12 Feb 2026 09:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41117</strong></p>
  <p>Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.  Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21720 – Every uncached /avatar/:hash request spawns a goroutine that refreshes the Grava...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21720</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21720</guid>
    <pubDate>Tue, 27 Jan 2026 09:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21720</strong></p>
  <p>Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21720">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22643 – In Grafana, an excessively long dashboard title or panel name will cause Chromiu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22643</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22643</strong></p>
  <p>In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22642 – An open redirect vulnerability has been identified in Grafana OSS organization s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22642</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22642</strong></p>
  <p>An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22641 – This vulnerability in Grafana's datasource proxy API allows authorization checks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22641</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22641</strong></p>
  <p>This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prome…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22640 – An access control vulnerability was discovered in Grafana OSS where an Organizat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22640</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22640</strong></p>
  <p>An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either: - Not part of any organization, or - Part of the same or…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22639 – Grafana is an open-source platform for monitoring and observability. The Grafana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22639</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22639</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22638 – A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22638</guid>
    <pubDate>Thu, 15 Jan 2026 14:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22638</strong></p>
  <p>A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is ins…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0713 – A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0713</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0713</strong></p>
  <p>A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dash…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0712 – An open redirect vulnerability has been identified in Grafana OSS that can be ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0712</guid>
    <pubDate>Thu, 15 Jan 2026 13:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0712</strong></p>
  <p>An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-41115 – SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in Apri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41115</guid>
    <pubDate>Fri, 21 Nov 2025 15:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41115</strong></p>
  <p>SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management.  In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling allows a malicious or compromised SCIM client to provision a user with a numeric ex…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-41116 – When using the Grafana Databricks Datasource Plugin,
if Oauth passthrough is ena...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41116</guid>
    <pubDate>Tue, 11 Nov 2025 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-41116</strong></p>
  <p>When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in   the wrong user identifier being used, and information for which the viewer is not authorized being returned.   This issue affects Grafana Databricks Datasource Plugin: from 1.6.…</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-653</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-3717 – When using the Grafana Snowflake Datasource Plugin,
if Oauth passthrough is enab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3717</guid>
    <pubDate>Tue, 11 Nov 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-3717</strong></p>
  <p>When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it  could result in   the wrong user identifier being used, and information for which the viewer is not authorized being returned.   This issue affects Grafana Snowflake Datasource Plugin: from 1.5.0…</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-653</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11539 – Grafana Image Renderer is vulnerable to remote code execution due to an arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11539</guid>
    <pubDate>Thu, 09 Oct 2025 08:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11539</strong></p>
  <p>Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then loaded by the Chromium process.  Instances are vulnerable if:  1. The default token ("authToken") is not c…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-10630 – Grafana is an open-source platform for monitoring and observability. Grafana-Zab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10630</guid>
    <pubDate>Fri, 19 Sep 2025 10:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-10630</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring.     Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-58746 – The Volkov Labs Business Links panel for Grafana provides an interface to naviga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58746</guid>
    <pubDate>Mon, 08 Sep 2025 23:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-58746</strong></p>
  <p>The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions. This is possible because the plugin allows arbitrary JavaScript code injection in…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-8341 – Grafana is an open-source platform for monitoring and observability. The Infinit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8341</guid>
    <pubDate>Mon, 04 Aug 2025 09:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-8341</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, and HTML endpoints.   If the plugin was configured to allow only certain URLs, an attacker could bypass this restriction using a specially crafted URL. This vulnerability is fixed in version 3.4.1.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6197 – An open redirect vulnerability has been identified in Grafana OSS organization s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6197</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6197</strong></p>
  <p>An open redirect vulnerability has been identified in Grafana OSS organization switching functionality.   Prerequisites for exploitation:  - Multiple organizations must exist in the Grafana instance  - Victim must be on a different organization than the one specified in the URL</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6023 – An open redirect vulnerability has been identified in Grafana OSS that can be ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6023</guid>
    <pubDate>Fri, 18 Jul 2025 08:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6023</strong></p>
  <p>An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0.  The open redirect can be chained with path traversal vulnerabilities to achieve XSS.  Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3415 – Grafana is an open-source platform for monitoring and observability. The Grafana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3415</guid>
    <pubDate>Thu, 17 Jul 2025 11:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3415</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission.  Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-1088 – In Grafana, an excessively long dashboard title or panel name will cause Chromiu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1088</guid>
    <pubDate>Wed, 18 Jun 2025 10:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-1088</strong></p>
  <p>In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3454 – This vulnerability in Grafana's datasource proxy API allows authorization checks...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3454</guid>
    <pubDate>Mon, 02 Jun 2025 11:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3454</strong></p>
  <p>This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.  Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.  The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Pro…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3260 – A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3260</guid>
    <pubDate>Mon, 02 Jun 2025 10:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3260</strong></p>
  <p>A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1).  Impact:  - Viewers can view all dashboards/folders regardless of permissions  - Editors can view/edit/delete all dashboards/folders regardless of permissions  - Editors can create…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3580 – An access control vulnerability was discovered in Grafana OSS where an Organizat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3580</guid>
    <pubDate>Fri, 23 May 2025 14:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3580</strong></p>
  <p>An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint.  The vulnerability can be exploited when:  1. An Organization administrator exists  2. The Server administrator is either:     - Not part of any organization, or    - Part of t…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4123 – A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4123</guid>
    <pubDate>Thu, 22 May 2025 08:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4123</strong></p>
  <p>A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is ins…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-11741 – Grafana is an open-source platform for monitoring and observability. 
The Grafan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11741</guid>
    <pubDate>Fri, 31 Jan 2025 16:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-11741</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.  The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission.  Fixed in versions 11.5.0, 11.4.1, 11.3.3,  11.2.6, 11.1.11, 11.0.11 and 10.4.15</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-9476 – A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Esca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9476</guid>
    <pubDate>Wed, 13 Nov 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-9476</strong></p>
  <p>A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51988 – RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51988</guid>
    <pubDate>Wed, 06 Nov 2024 20:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51988</strong></p>
  <p>RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been address…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-9264 – The SQL Expressions experimental feature of Grafana allows for the evaluation of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-9264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-9264</guid>
    <pubDate>Fri, 18 Oct 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-9264</strong></p>
  <p>The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack.  The `duckdb` binary must be present in Grafana'…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-9264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-8118 – In Grafana, the wrong permission is applied to the alert rule write API endpoint...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8118</guid>
    <pubDate>Thu, 26 Sep 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-8118</strong></p>
  <p>In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-653</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8996 – Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8996</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8996</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8996</strong></p>
  <p>Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8996">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-8975 – Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8975</guid>
    <pubDate>Wed, 25 Sep 2024 17:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-8975</strong></p>
  <p>Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8986 – The grafana plugin SDK bundles build metadata into the binaries it compiles; thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8986</guid>
    <pubDate>Thu, 19 Sep 2024 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8986</strong></p>
  <p>The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`.   If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-5526 – Grafana OnCall is an easy-to-use on-call management tool that will help reduce t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5526</guid>
    <pubDate>Wed, 05 Jun 2024 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-5526</strong></p>
  <p>Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers.  Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vulnerability in the webhook functionallity.   This issue was fixed in version 1.5.2</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31634 – In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31634</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31634</guid>
    <pubDate>Wed, 27 Mar 2024 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31634</strong></p>
  <p>In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for the TeslaMate instance, an attacker can switch the port to 3000 to enter Grafana for remote operations. At that time, the default username and password can be used to enter the Grafana management console without logging in, a related issue to CVE-…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31634">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1313 – It is possible for a user in a different organization from the owner of a snapsh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1313</guid>
    <pubDate>Tue, 26 Mar 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1313</strong></p>
  <p>It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/<key> using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot in question, but due to a bug in the authorization logic, deletion requests issue…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44090 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44090</guid>
    <pubDate>Tue, 19 Mar 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44090</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-1442 – A user with the permissions to create a data source can use Grafana API to creat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1442</guid>
    <pubDate>Thu, 07 Mar 2024 18:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-1442</strong></p>
  <p>A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-5123 – The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-js...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5123</guid>
    <pubDate>Wed, 14 Feb 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-5123</strong></p>
  <p>The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of the dashboard-supplied path parameter, it was possible to include path traversal…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-5122 – Grafana is an open-source platform for monitoring and observability. The CSV dat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-5122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-5122</guid>
    <pubDate>Wed, 14 Feb 2024 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-5122</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no path (e.g.  https://www.example.com/ https://www.example.com/` ), requests to an…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-5122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36649 – Insertion of sensitive information in the centralized (Grafana) logging system i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36649</guid>
    <pubDate>Tue, 12 Dec 2023 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36649</strong></p>
  <p>Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki REST API without authentication.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3010 – Grafana is an open-source platform for monitoring and observability. 

The World...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3010</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3010</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4399 – Grafana is an open-source platform for monitoring and observability. 

In Grafan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4399</guid>
    <pubDate>Tue, 17 Oct 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4399</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts.  However, the restriction can be bypassed used punycode encoding of the characters in the request address.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-183</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4457 – Grafana is an open-source platform for monitoring and observability.

The Google...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4457</guid>
    <pubDate>Mon, 16 Oct 2023 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4457</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.  The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.  The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.  This vulnerability was fixed in version 1.2.2.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-4822 – Grafana is an open-source platform for monitoring and observability. The vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4822</guid>
    <pubDate>Mon, 16 Oct 2023 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-4822</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.  It also allows an Organization Admin to assign or…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-3128 – Grafana is validating Azure AD accounts based on the email claim. 

On Azure AD,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3128</guid>
    <pubDate>Thu, 22 Jun 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-3128</strong></p>
  <p>Grafana is validating Azure AD accounts based on the email claim.   On Azure AD, the profile email field is not unique and can be easily modified.   This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2801 – Grafana is an open-source platform for monitoring and observability. 

Using pub...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2801</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2801</guid>
    <pubDate>Tue, 06 Jun 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2801</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance.  The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly.  This might enabl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-820</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2801">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-2183 – Grafana is an open-source platform for monitoring and observability. 

The optio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2183</guid>
    <pubDate>Tue, 06 Jun 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-2183</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API does not check access to this function.  This might enable malicious users to abuse the functionality by sending multiple a…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-1387 – Grafana is an open-source platform for monitoring and observability. 

Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1387</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1387</guid>
    <pubDate>Wed, 26 Apr 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-1387</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token.   By enabling the "url_login" configuration option (disabled by default), a JWT might be sent to data sources. If an attacker has access to the data source, the leaked t…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1387">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-24831 – Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24831</guid>
    <pubDate>Mon, 17 Apr 2023 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-24831</strong></p>
  <p>Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3.  Attackers could login without authorization. This is fixed in 0.13.4.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-1410 – Grafana is an open-source platform for monitoring and observability. 

Grafana h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1410</guid>
    <pubDate>Thu, 23 Mar 2023 08:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-1410</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip.   The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized.  An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-22462 – Grafana is an open-source platform for monitoring and observability. On 2023-01-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22462</guid>
    <pubDate>Thu, 02 Mar 2023 01:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-22462</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requires several user interactions in order to be fully exploited. The vulnerability was possible due to React's render cycle that will pass though the u…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0594 – Grafana is an open-source platform for monitoring and observability. 

Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0594</guid>
    <pubDate>Wed, 01 Mar 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0594</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization.   The stored XSS vulnerability was possible due the value of a span's attributes/resources were not properly sanitized and this will be rendered when the span's attributes/resources are expanded.  An attacker needs to have the…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0507 – Grafana is an open-source platform for monitoring and observability. 

Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0507</guid>
    <pubDate>Wed, 01 Mar 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0507</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability.   Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.   The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.   An atta…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23498 – Grafana is an open-source platform for monitoring and observability. When dataso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23498</guid>
    <pubDate>Fri, 03 Feb 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23498</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patche…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39324 – Grafana is an open-source platform for monitoring and observability. Prior to ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39324</guid>
    <pubDate>Fri, 27 Jan 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39324</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The `Open origina…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-23552 – Grafana is an open-source platform for monitoring and observability. Starting wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23552</guid>
    <pubDate>Fri, 27 Jan 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-23552</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized u…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-44643 – A vulnerability in the label-based access control of Grafana Labs Grafana Enterp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-44643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-44643</guid>
    <pubDate>Tue, 20 Dec 2022 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-44643</strong></p>
  <p>A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Graf…</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-44643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46156 – The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46156</guid>
    <pubDate>Wed, 30 Nov 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46156</strong></p>
  <p>The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The authentication token used to communicate with the Synthetic Monitoring API is exposed through a debugging endpoint. This to…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39307 – Grafana is an open-source platform for monitoring and observability. When using ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39307</guid>
    <pubDate>Wed, 09 Nov 2022 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39307</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39306 – Grafana is an open-source platform for monitoring and observability. Versions pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39306</guid>
    <pubDate>Wed, 09 Nov 2022 22:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39306</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an i…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39328 – Grafana is an open-source platform for monitoring and observability. Versions st...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39328</guid>
    <pubDate>Tue, 08 Nov 2022 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39328</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39229 – Grafana is an open source data visualization platform for metrics, logs, and tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39229</guid>
    <pubDate>Thu, 13 Oct 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39229</strong></p>
  <p>Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39201 – Grafana is an open source observability and data visualization platform. Startin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39201</guid>
    <pubDate>Thu, 13 Oct 2022 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39201</strong></p>
  <p>Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31130 – Grafana is an open source observability and data visualization platform. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31130</guid>
    <pubDate>Thu, 13 Oct 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31130</strong></p>
  <p>Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31123 – Grafana is an open source observability and data visualization platform. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31123</guid>
    <pubDate>Thu, 13 Oct 2022 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31123</strong></p>
  <p>Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not instal…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36062 – Grafana is an open-source platform for monitoring and observability. In versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36062</guid>
    <pubDate>Thu, 22 Sep 2022 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36062</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating l…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-35957 – Grafana is an open-source platform for monitoring and observability. Versions pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35957</guid>
    <pubDate>Tue, 20 Sep 2022 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-35957</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following th…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38370 – Apache IoTDB grafana-connector version 0.13.0 contains an interface without auth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38370</guid>
    <pubDate>Mon, 05 Sep 2022 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38370</strong></p>
  <p>Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31176 – Grafana Image Renderer is a Grafana backend plugin that handles rendering of pan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31176</guid>
    <pubDate>Fri, 02 Sep 2022 21:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31176</strong></p>
  <p>Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana)…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2531 – An issue has been discovered in GitLab EE affecting all versions starting from 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2531</guid>
    <pubDate>Fri, 05 Aug 2022 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2531</strong></p>
  <p>An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific conditions allowing unauthenticated users to perform queries through a path traversal vulnerability.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31107 – Grafana is an open-source platform for monitoring and observability. In versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31107</guid>
    <pubDate>Fri, 15 Jul 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31107</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31097 – Grafana is an open-source platform for monitoring and observability. Versions on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31097</guid>
    <pubDate>Fri, 15 Jul 2022 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31097</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32276 – Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snaps...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32276</guid>
    <pubDate>Fri, 17 Jun 2022 13:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32276</strong></p>
  <p>Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32275 – Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32275</guid>
    <pubDate>Mon, 06 Jun 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32275</strong></p>
  <p>Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29170 – Grafana is an open-source platform for monitoring and observability. In Grafana ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29170</guid>
    <pubDate>Fri, 20 May 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29170</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malici…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-28660 – The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28660</guid>
    <pubDate>Fri, 20 May 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-28660</strong></p>
  <p>The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-29171 – Sourcegraph is a fast and featureful code search and navigation engine. Versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29171</guid>
    <pubDate>Fri, 06 May 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-29171</strong></p>
  <p>Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site admins to specify a `callsignCommand`, which is used to obtain the Phabricator metadata for a Gitolite repository. An administrator who is able to edit or add a G…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24812 – Grafana is an open-source platform for monitoring and observability. When fine-g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24812</guid>
    <pubDate>Tue, 12 Apr 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24812</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent requests with any API Key evaluate to the same permissions as the previous requests.…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-26148 – An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-26148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-26148</guid>
    <pubDate>Mon, 21 Mar 2022 20:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-26148</strong></p>
  <p>An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21713 – Grafana is an open-source platform for monitoring and observability. Affected ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21713</guid>
    <pubDate>Tue, 08 Feb 2022 21:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21713</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of avai…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21703 – Grafana is an open-source platform for monitoring and observability. Affected ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21703</guid>
    <pubDate>Tue, 08 Feb 2022 21:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21703</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an au…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21702 – Grafana is an open-source platform for monitoring and observability. In affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21702</guid>
    <pubDate>Tue, 08 Feb 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21702</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource for a specific Grafana instance or either set u…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-23126 – TeslaMate before 1.25.1 (when using the default Docker configuration) allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23126</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23126</guid>
    <pubDate>Mon, 24 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-23126</strong></p>
  <p>TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, start Keyless Driving, and interfere with vehicle operation en route. This occurs because an attacker can leverage Grafana login access to obtain a token for Tesla API calls.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23126">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-21673 – Grafana is an open-source platform for monitoring and observability. In affected...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-21673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-21673</guid>
    <pubDate>Tue, 18 Jan 2022 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-21673</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-21673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-43815 – Grafana is an open-source platform for monitoring and observability. Grafana pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43815</guid>
    <pubDate>Fri, 10 Dec 2021 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-43815</strong></p>
  <p>Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in scope, and only allows access to files with the extension .csv to authenticated users…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43815">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
