Show filters
90 Total Results
Displaying 71-80 of 90
Sort by:
Attacker Value
Unknown
CVE-2020-27846
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
0
Attacker Value
Unknown
CVE-2020-24303
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
0
Attacker Value
Unknown
CVE-2019-19499
Disclosure Date: August 28, 2020 (last updated February 22, 2025)
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.
0
Attacker Value
Unknown
CVE-2020-11110
Disclosure Date: July 27, 2020 (last updated February 21, 2025)
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
0
Attacker Value
Unknown
CVE-2018-18624
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
0
Attacker Value
Unknown
CVE-2018-18625
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
0
Attacker Value
Unknown
CVE-2018-18623
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
0
Attacker Value
Unknown
CVE-2020-13429
Disclosure Date: May 24, 2020 (last updated February 21, 2025)
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
0
Attacker Value
Unknown
CVE-2020-13430
Disclosure Date: May 24, 2020 (last updated February 21, 2025)
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
0
Attacker Value
Unknown
CVE-2020-12459
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
0