Catalog / Grafana

Grafana security advisories

All 28 advisories Grafana has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
2828 carry a CVE
critical
3
high
7
medium
18
Fix in the archive
0of 28 matched to a release
Oldest
5 Oct 20214.9 years ago

28 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2023-22462medium

Stored XSS in Text plugin

GHSA-7rqg-hjwc-6mjf
CVE-2022-23498high

Use of Cache Containing Sensitive Information

GHSA-2j8f-6whh-frc8Fixed in 9.3.4, not held here
CVE-2022-39324medium

Spoofing originalUrl of snapshots

GHSA-4724-7jwc-3fpw
CVE-2022-41912high

SAML privilege escalation

GHSA-5hcf-rqj9-xh96Fixed in 9.3.2, not held here
CVE-2022-23552high

Stored XSS in ResourcePicker component

GHSA-8xmm-x63g-f6xv
CVE-2022-39306medium

Email addresses and usernames can not be trusted

GHSA-2x6g-h2hg-rq84
CVE-2022-39307medium

User enumeration via forget password

GHSA-3p62-42x7-gxg5Fixed in 9.2.4, not held here
CVE-2022-39328critical

Race condition allowing privilege escalation

GHSA-vqc4-mpj8-jxchFixed in 9.2.4, not held here
CVE-2022-31123medium

Plugin signature bypass

GHSA-rhxj-gh46-jvw8Fixed in 9.1.8, not held here
CVE-2022-31130medium

Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins

GHSA-jv32-5578-pxjcFixed in 9.1.8, not held here
CVE-2022-39201medium

Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

GHSA-x744-mm8v-vpgrFixed in 9.1.8, not held here
CVE-2022-39229medium

Using email as a username can block other users from signing in

GHSA-gj7m-853r-289rFixed in 9.1.8, not held here
CVE-2022-35957medium

Escalation from admin to server admin when auth proxy is used

GHSA-ff5c-938w-8c9qFixed in 9.1.6, not held here
CVE-2022-36062medium

Grafana folders admin only permission privilege escalation

GHSA-p978-56hq-r492Fixed in 9.1.6, not held here
CVE-2022-31097high

Stored XSS in Unified Alerting

GHSA-vw7q-p2qg-4m5fFixed in 9.0.3, not held here
CVE-2022-31107high

Grafana account takeover via OAuth vulnerability

GHSA-mx47-6497-3fv2Fixed in 9.0.3, not held here
CVE-2022-29170medium

CVE-2022-29170: Grafana Enterprise datasource network restrictions bypass via HTTP redirects

GHSA-9rrr-6fq2-4f99Fixed in 7.5.16, not held here
CVE-2022-24812high

CVE-2022-24812: Grafana Enterprise fine-grained access control API Key privilege escalation

GHSA-82gq-xfg3-5j7vFixed in 8.4.6, not held here
CVE-2022-21702medium

CVE-2022-21702: Grafana proxy XSS

GHSA-xc3p-28hw-q24gFixed in 8.3.5, not held here
CVE-2022-21703medium

CVE-2022-21703: Grafana Cross Site Request Forgery (CSRF)

GHSA-cmf4-h3xc-jw8wFixed in 8.3.5, not held here
CVE-2022-21713medium

CVE-2022-21713: Grafana Teams API IDOR

GHSA-63g3-9jq3-mccvFixed in 8.3.5, not held here
CVE-2022-21673medium

Forward OAuth Identity Token can allow users to access some data sources

GHSA-8wjh-59cw-9xh4
CVE-2021-43813medium

CVE-2021-43813: Grafana directory traversal for `.md` files, 5.0.0 - 8.3.1

GHSA-c3q8-26ph-9g2qFixed in 8.3.2, not held here
CVE-2021-43815medium

CVE-2021-43815: Grafana directory traversal for `.csv` files, 8.0.0-beta3 - 8.3.1

GHSA-7533-c8qv-jm9mFixed in 8.3.2, not held here
CVE-2021-43798high

Grafana path traversal

GHSA-8pjx-jj86-j47pFixed in 8.3.1, not held here
CVE-2021-41244critical

Fine-grained access control enables organization admins to create/modify/delete user roles in other organization

GHSA-mpwp-42x6-4wmxFixed in 8.2.4, not held here
CVE-2021-41174medium

XSS vulnerability allowing arbitrary JavaScript execution

GHSA-3j9m-hcv9-rpj8Fixed in 8.2.3, not held here
CVE-2021-39226critical

CVE-2021-39226 Snapshot authentication bypass

GHSA-69j6-29vr-p3j9Fixed in 7.5.11, not held here