data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2022-31097 – Stored XSS in Grafana's Unified Alerting
https://notcve.org/view.php?id=CVE-2022-31097
15 Jul 2022 — Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.... • https://github.com/grafana/grafana/security/advisories/GHSA-vw7q-p2qg-4m5f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2022-32276
https://notcve.org/view.php?id=CVE-2022-32276
17 Jun 2022 — Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability ** EN DISPUTA ** Grafana versión 8.4.3, permite el acceso no autenticado por medio de (por ejemplo) un URI /dashboard/snapshot/*?orgId=0. NOTA: el proveedor considera que esto es un error de la interfaz de usuario, no una vulnerabilidad • https://github.com/BrotherOfJhonny/grafana/blob/main/README.md • CWE-287: Improper Authentication •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2022-32275
https://notcve.org/view.php?id=CVE-2022-32275
06 Jun 2022 — Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content ** EN DISPUTA ** Grafana versión 8.4.3, permite leer archivos por medio de (por ejemplo) un /dashboard/snapshot/%7B%7Bconstructor.constructor"/. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTA: la posición del proveedor es que n... • https://github.com/BrotherOfJhonny/grafana • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2022-29170 – Grafana Enterprise datasource network restrictions bypass via HTTP redirects
https://notcve.org/view.php?id=CVE-2022-29170
20 May 2022 — Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only ... • https://github.com/yijikeji/CVE-2022-29170 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
data:image/s3,"s3://crabby-images/6a7b9/6a7b99c8f15dbc13786e9612de788fc0ac15e1c2" alt=""
CVE-2022-24812 – FGAC API Key privilege escalation in Grafana
https://notcve.org/view.php?id=CVE-2022-24812
12 Apr 2022 — Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent requests with any API Key evaluate to the same permissions as the previous requests. This can lead to an escalation of privileges, when for example a first request is made with Admin permissions, a... • https://github.com/grafana/grafana/security/advisories/GHSA-82gq-xfg3-5j7v • CWE-269: Improper Privilege Management •