Stored XSS in Text plugin
Grafana security advisories
All 28 advisories Grafana has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 2828 carry a CVE
- critical
- 3
- high
- 7
- medium
- 18
- Fix in the archive
- 0of 28 matched to a release
- Oldest
- 5 Oct 20214.9 years ago
28 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productUse of Cache Containing Sensitive Information
Spoofing originalUrl of snapshots
SAML privilege escalation
Stored XSS in ResourcePicker component
Email addresses and usernames can not be trusted
User enumeration via forget password
Race condition allowing privilege escalation
Plugin signature bypass
Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins
Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins
Using email as a username can block other users from signing in
Escalation from admin to server admin when auth proxy is used
Grafana folders admin only permission privilege escalation
Stored XSS in Unified Alerting
Grafana account takeover via OAuth vulnerability
CVE-2022-29170: Grafana Enterprise datasource network restrictions bypass via HTTP redirects
CVE-2022-24812: Grafana Enterprise fine-grained access control API Key privilege escalation
CVE-2022-21702: Grafana proxy XSS
CVE-2022-21703: Grafana Cross Site Request Forgery (CSRF)
CVE-2022-21713: Grafana Teams API IDOR
Forward OAuth Identity Token can allow users to access some data sources
CVE-2021-43813: Grafana directory traversal for `.md` files, 5.0.0 - 8.3.1
CVE-2021-43815: Grafana directory traversal for `.csv` files, 8.0.0-beta3 - 8.3.1
Grafana path traversal
Fine-grained access control enables organization admins to create/modify/delete user roles in other organization
XSS vulnerability allowing arbitrary JavaScript execution
CVE-2021-39226 Snapshot authentication bypass