Show filters
90 Total Results
Displaying 81-90 of 90
Sort by:
Attacker Value
Unknown

CVE-2020-12458

Disclosure Date: April 29, 2020 (last updated February 21, 2025)
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
Attacker Value
Unknown

CVE-2020-12052

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
Attacker Value
Unknown

CVE-2020-12245

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
Attacker Value
Unknown

CVE-2019-15635

Disclosure Date: September 23, 2019 (last updated November 27, 2024)
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.
Attacker Value
Unknown

CVE-2019-13068

Disclosure Date: June 30, 2019 (last updated November 27, 2024)
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
0
Attacker Value
Unknown

CVE-2015-9282

Disclosure Date: February 06, 2019 (last updated November 27, 2024)
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.
0
Attacker Value
Unknown

CVE-2018-1000816

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..
0
Attacker Value
Unknown

CVE-2018-19039

Disclosure Date: December 13, 2018 (last updated November 27, 2024)
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
0
Attacker Value
Unknown

CVE-2018-15727

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
0
Attacker Value
Unknown

CVE-2018-12099

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
0