← Catalog
Gr

Grafana

Observability & Monitoring latest v13.0.5 · via GitHub Releases
MODERATE CVE-2026-33381 Wed, May 13

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

GHSA-wfhv-mj62-f5xh CVE-2026-33381 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N github.com/grafana/grafana introduced: 0 fixed: 1.9.2-0.20260513165311-fb7336fc36c1
MODERATE CVE-2026-33380 Wed, May 13

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

GHSA-gxcp-jjxh-rwp4 CVE-2026-33380 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N github.com/grafana/grafana introduced: 0 fixed: 1.9.2-0.20260513165311-fb7336fc36c1
MODERATE CVE-2026-27877 Fri, Mar 27

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.

GHSA-3q27-7qjq-p9c5 CVE-2026-27877 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N github.com/grafana/grafana introduced: 9.3.0 github.com/grafana/grafana introduced: 12.0.0 github.com/grafana/grafana introduced: 12.2.0 github.com/grafana/grafana introduced: 12.3.0 github.com/grafana/grafana introduced: 12.4.0 github.com/grafana/grafana introduced: 1.9.2-0.20221116104934-4ee83a5f2bf4 fixed: 1.9.2-0.20260325055210-3522153e07b4
MODERATE CVE-2026-21724 Thu, Mar 26

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission. A patched version is available at https://github.com/grafana/grafana/releases/tag/v12.3.6.

GHSA-7g92-g4vh-hp84 CVE-2026-21724 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N github.com/grafana/grafana introduced: 0 fixed: 1.9.2-0.20260323180334-daffe750de85
MODERATE CVE-2025-41117 Thu, Feb 12

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

GHSA-cqp7-wf4c-3xgc CVE-2025-41117 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N github.com/grafana/grafana introduced: 12.2.0 fixed: 12.2.5 github.com/grafana/grafana introduced: 12.3.0 fixed: 12.3.3
CRITICAL CVE-2025-41115 Fri, Nov 21

SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management.

GHSA-w62r-7c53-fmc5 CVE-2025-41115 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H github.com/grafana/grafana introduced: 12.0.0 fixed: 12.0.7 github.com/grafana/grafana introduced: 12.1.0 fixed: 12.1.4 github.com/grafana/grafana introduced: 12.2.0 fixed: 12.2.2 github.com/grafana/grafana introduced: 1.9.2-0.20250310110405-e6fdb746f235 fixed: 1.9.2-0.20251106142618-ca5d89812015
HIGH CVE-2025-6023 Fri, Jul 18

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01

GHSA-vqph-p5vc-g644 CVE-2025-6023 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L github.com/grafana/grafana introduced: 0 fixed: 1.9.2-0.20250521205822-0ba0b99665a9
MODERATE CVE-2025-3415 Thu, Jul 17

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01.

GHSA-46m5-8hpj-p5p5 CVE-2025-3415 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N github.com/grafana/grafana introduced: 0 fixed: 1.9.2-0.20250514160932-04111e9f2afd
LOW CVE-2025-1088 Wed, Jun 18

In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

GHSA-crvv-6w6h-cv34 CVE-2025-1088 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L github.com/grafana/grafana introduced: 0.0.1-test fixed: 11.6.2 github.com/grafana/grafana introduced: 0 fixed: 0.0.0-20250521211231-e0ba4b480954
HIGH CVE-2025-3260 Mon, Jun 2

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1).

GHSA-3px7-c4j3-576r CVE-2025-3260 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L github.com/grafana/grafana introduced: 0.0.0-20250114093457-36d6fad421fb fixed: 0.0.0-20250521183405-c7a690348df7
MODERATE CVE-2025-3454 Mon, Jun 2

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

GHSA-9j65-rv5x-4vrf CVE-2025-3454 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N github.com/grafana/grafana introduced: 0.0.0-20210414170620-dadccdda06e6 fixed: 0.0.0-20250424191517-1f707d16ed5d
HIGH CVE-2025-4123 Thu, May 22

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF.

GHSA-q53q-gxq9-mgrj CVE-2025-4123 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L github.com/grafana/grafana introduced: 0 fixed: 0.0.0-20250521183405-c7a690348df7
MODERATE CVE-2024-11741 Fri, Jan 31

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15

GHSA-wxcc-2f3q-4h58 CVE-2024-11741 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N github.com/grafana/grafana introduced: 11.4.0 fixed: 11.4.1 github.com/grafana/grafana introduced: 11.3.0 fixed: 11.3.3 github.com/grafana/grafana introduced: 11.2.0 fixed: 11.2.6 github.com/grafana/grafana introduced: 11.1.0 fixed: 11.1.11 github.com/grafana/grafana introduced: 11.0.0 fixed: 11.0.11 github.com/grafana/grafana introduced: 1.9.2 fixed: 10.4.15 … +2 more ranges
LOW CVE-2024-10452 Tue, Oct 29

Organization admins can delete pending invites created in an organization they are not part of.

GHSA-66c4-2g2v-54qw CVE-2024-10452 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N github.com/grafana/grafana introduced: 0 last_affected: 10.4.0
CRITICAL CVE-2024-9264 Fri, Oct 18

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack.

GHSA-q99m-qcv4-fpm7 CVE-2024-9264 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H github.com/grafana/grafana introduced: 11.0.0 fixed: 11.0.6+security-01 github.com/grafana/grafana introduced: 11.1.0 fixed: 11.1.7+security-01 github.com/grafana/grafana introduced: 11.2.0 fixed: 11.2.2+security-01
MODERATE CVE-2024-6322 Tue, Aug 20

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

GHSA-hh8p-374f-qgr5 CVE-2024-6322 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L github.com/grafana/grafana introduced: 11.1.0 fixed: 11.1.1 github.com/grafana/grafana introduced: 11.1.2 fixed: 11.1.3 github.com/grafana/grafana introduced: 0.0.0-20240521130516-0072e4a92d89 fixed: 0.0.0-20240725142242-c326d865c58b github.com/grafana/grafana introduced: 1.9.2-0.20240521130516-0072e4a92d89 fixed: 1.9.2-0.20240725142242-c326d865c58b
HIGH CVE-2022-36062 Tue, May 14

Today we are releasing Grafana 9.1.6, 9.0.9, 8.5.13. This patch release includes a Moderate severity security fix for CVE-2022-36062 that affects Grafana instances which are using Grafana role-based access control (RBAC).

GHSA-p978-56hq-r492 CVE-2022-36062 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L github.com/grafana/grafana introduced: 8.5.0 fixed: 8.5.13 github.com/grafana/grafana introduced: 9.0.0 fixed: 9.0.9 github.com/grafana/grafana introduced: 9.1.0 fixed: 9.1.6
HIGH CVE-2022-39201 Tue, May 14

Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-39201 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues.

GHSA-x744-mm8v-vpgr CVE-2022-39201 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H github.com/grafana/grafana introduced: 5.0.0-beta1 fixed: 8.5.14 github.com/grafana/grafana introduced: 9.0.0 fixed: 9.1.8
MODERATE CVE-2022-39229 Tue, May 14

Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-39229 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues.

GHSA-gj7m-853r-289r CVE-2022-39229 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L github.com/grafana/grafana introduced: 0 fixed: 8.5.14 github.com/grafana/grafana introduced: 9.0.0 fixed: 9.1.8
HIGH CVE-2022-39306 Tue, May 14

Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes moderate severity security fixes for CVE-2022-39306. We are also releasing security patches for Grafana 8.5.15 to fix these issues.

GHSA-2x6g-h2hg-rq84 CVE-2022-39306 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N github.com/grafana/grafana introduced: 8.0.0 fixed: 8.5.15 github.com/grafana/grafana introduced: 9.0.0 fixed: 9.2.4
HIGH CVE-2022-39307 Tue, May 14

Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes moderate security fixes for CVE-2022-39307. We are also releasing security patches for Grafana 8.5.15 to fix these issues.

GHSA-3p62-42x7-gxg5 CVE-2022-39307 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L github.com/grafana/grafana introduced: 9.0.0 fixed: 9.2.4 github.com/grafana/grafana introduced: 0 fixed: 8.5.15
MODERATE CVE-2022-39324 Tue, May 14

To create a snapshot (and insert an arbitrary URL) the built-in role Viewer is sufficient. When a dashboard is shared as a local snapshot, the following three fields are offered in the web UI for a user to fill out: • Snapshotname • Expire • Timeout(seconds) After the user confirms creation of the snapshot (i.e. clicks the ”Local Snapshot” button) an HTTP POST request is sent to the Grafana server. The HTTP request contains additional parameters that are not visible in the web UI.

GHSA-4724-7jwc-3fpw CVE-2022-39324 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L github.com/grafana/grafana introduced: 9.0.0 fixed: 9.2.8 github.com/grafana/grafana introduced: 0 fixed: 8.5.16
CRITICAL CVE-2022-39328 Tue, May 14

Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes critical security fixes for CVE-2022-39328. Release 9.2.4, latest patch, also containing security fix: - [Download Grafana 9.2.4](https://grafana.com/grafana/download/9.2.4) Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro.

GHSA-vqc4-mpj8-jxch CVE-2022-39328 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H github.com/grafana/grafana introduced: 9.2.0 fixed: 9.2.4
HIGH CVE-2022-35957 Tue, May 14

Today we are releasing Grafana 9.1.6, 9.0.9, 8.5.13. This patch release includes a Moderate severity security fix for CVE-2022-35957 that affects Grafana instances which are using Grafana [Auth Proxy](https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/#configure-auth-proxy-authentication).

GHSA-ff5c-938w-8c9q CVE-2022-35957 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H github.com/grafana/grafana introduced: 9.1.0 fixed: 9.1.6 github.com/grafana/grafana introduced: 9.0.0 fixed: 9.0.9 github.com/grafana/grafana introduced: 0 fixed: 8.5.13
MODERATE CVE-2022-31130 Tue, May 14

Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-31130 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues.

GHSA-jv32-5578-pxjc CVE-2022-31130 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N github.com/grafana/grafana introduced: 9.0.0 fixed: 9.1.8 github.com/grafana/grafana introduced: 7.0.0 fixed: 8.5.14
HIGH CVE-2022-31123 Tue, May 14

Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-31123 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues.

GHSA-rhxj-gh46-jvw8 CVE-2022-31123 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L github.com/grafana/grafana introduced: 9.0.0 fixed: 9.1.8 github.com/grafana/grafana introduced: 7.0.0 fixed: 8.5.14
HIGH CVE-2022-31107 Tue, May 14

Today we are releasing Grafana 8.3.10, 8.4.10, 8.5.9 and 9.0.3. This patch release includes a HIGH severity security fix for an Oauth takeover vulnerability in Grafana.

GHSA-mx47-6497-3fv2 CVE-2022-31107 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L github.com/grafana/grafana introduced: 5.3.0-beta1 fixed: 8.3.10 github.com/grafana/grafana introduced: 8.4.0 fixed: 8.4.10 github.com/grafana/grafana introduced: 8.5.0 fixed: 8.5.9 github.com/grafana/grafana introduced: 9.0.0 fixed: 9.0.3
MODERATE CVE-2022-21713 Tue, May 14

Today we are releasing Grafana 8.3.5 and 7.5.14. This patch release includes MEDIUM severity security fix for Grafana Teams API IDOR.

GHSA-63g3-9jq3-mccv CVE-2022-21713 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N github.com/grafana/grafana introduced: 5.0.0-beta1 fixed: 7.5.15 github.com/grafana/grafana introduced: 8.0.0 fixed: 8.3.5
MODERATE CVE-2022-31097 Tue, May 14

Today we are releasing Grafana 8.3.10, 8.4.10, 8.5.9 and 9.0.3. This patch release includes a HIGH severity security fix for a stored Cross Site Scripting in Grafana.

GHSA-vw7q-p2qg-4m5f CVE-2022-31097 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N github.com/grafana/grafana introduced: 9.0.0 fixed: 9.0.3 github.com/grafana/grafana introduced: 8.5.0 fixed: 8.5.9 github.com/grafana/grafana introduced: 8.4.0 fixed: 8.4.10 github.com/grafana/grafana introduced: 8.0.0 fixed: 8.3.10
MODERATE CVE-2022-21702 Tue, May 14

Today we are releasing Grafana 8.3.5 and 7.5.15. This patch release includes MEDIUM severity security fix for XSS for Grafana.

GHSA-xc3p-28hw-q24g CVE-2022-21702 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N github.com/grafana/grafana introduced: 2.0.0-beta1 fixed: 7.5.15 github.com/grafana/grafana introduced: 8.0.0 fixed: 8.3.5
MODERATE CVE-2021-43815 Tue, May 14

Today we are releasing Grafana `8.3.2` and `7.5.12`. This patch release includes a moderate severity security fix for directory traversal for arbitrary `.csv` files. It only affects instances that have the developer testing tool called [TestData DB data source](https://grafana.com/docs/grafana/latest/datasources/testdata/) enabled and configured.

GHSA-7533-c8qv-jm9m CVE-2021-43815 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N github.com/grafana/grafana introduced: 8.0.0-beta3 fixed: 8.3.2
CRITICAL CVE-2021-41244 Tue, May 14

### Impact On Nov. 2, during an internal security audit, we discovered that when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance, Grafana 8.0 introduced a mechanism which allowed users with the Organization Admin role to list, add, remove, and update users’ roles in other organizations in which they are not an admin.

GHSA-mpwp-42x6-4wmx CVE-2021-41244 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H github.com/grafana/grafana introduced: 8.0.0 fixed: 8.2.4
HIGH CVE-2024-1313 Fri, Apr 5

### Summary The ***DELETE /api/snapshots/{key}*** endpoint allows any Grafana user to delete snapshots if the user is NOT in the organization of the snapshot ### Details An attacker (a user without organization affiliation or with a "no basic role" in an organization other than the one where the dashboard exists), knowing the key or URL of a snapshot created by any user (including Grafana admins), can delete a snapshot (It is not feasible using UI), resulting in a BOLA vulnerability.

GHSA-67rv-qpw2-6qrr CVE-2024-1313 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N github.com/grafana/grafana introduced: 9.5.0 fixed: 9.5.18 github.com/grafana/grafana introduced: 10.0.0 fixed: 10.0.13 github.com/grafana/grafana introduced: 10.1.0 fixed: 10.1.9 github.com/grafana/grafana introduced: 10.2.0 fixed: 10.2.6 github.com/grafana/grafana introduced: 10.3.0 fixed: 10.3.5
HIGH CVE-2024-1442 Thu, Mar 7

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

GHSA-5mxf-42f5-j782 CVE-2024-1442 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L github.com/grafana/grafana introduced: 8.5.0 fixed: 9.5.7 github.com/grafana/grafana introduced: 10.0.0 fixed: 10.0.12 github.com/grafana/grafana introduced: 10.1.0 fixed: 10.1.8 github.com/grafana/grafana introduced: 10.2.0 fixed: 10.2.5 github.com/grafana/grafana introduced: 10.3.0 fixed: 10.3.4
MODERATE CVE-2023-6152 Tue, Feb 13

### Summary Email validation can easily be bypassed because `verify_email_enabled` option enable email validation at sign up only. A user changing it's email after signing up (and verifying it) can change it without verification in `/profile`. This can be used to prevent legitimate owner of the email address from signing up.

GHSA-3hv4-r2fm-h27f CVE-2023-6152 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L github.com/grafana/grafana introduced: 2.5.0 fixed: 9.5.16 github.com/grafana/grafana introduced: 10.0.0 fixed: 10.0.11 github.com/grafana/grafana introduced: 10.1.0 fixed: 10.1.7 github.com/grafana/grafana introduced: 10.2.0 fixed: 10.2.4 github.com/grafana/grafana introduced: 10.3.0 fixed: 10.3.3
HIGH CVE-2021-43798 Thu, Feb 1

Today we are releasing Grafana 8.3.1, 8.2.7, 8.1.8, 8.0.7. This patch release includes a high severity security fix that affects Grafana versions from v8.0.0-beta1 through v8.3.0.

GHSA-8pjx-jj86-j47p CVE-2021-43798 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H github.com/grafana/grafana introduced: 8.3.0 fixed: 8.3.1 github.com/grafana/grafana introduced: 8.2.0 fixed: 8.2.7 github.com/grafana/grafana introduced: 8.1.0 fixed: 8.1.8 github.com/grafana/grafana introduced: 8.0.0-beta1 fixed: 8.0.7
MODERATE CVE-2018-12099 Wed, Jan 31

Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

GHSA-v5gq-qvjq-8p53 CVE-2018-12099 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N github.com/grafana/grafana introduced: 0 fixed: 5.2.0-beta1
MODERATE CVE-2019-19499 Wed, Jan 31

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

GHSA-4pwp-cx67-5cpx CVE-2019-19499 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P github.com/grafana/grafana introduced: 0 fixed: 6.4.4
MODERATE CVE-2018-18625 Tue, Jan 30

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

GHSA-6wh2-8hw7-jw94 CVE-2018-18625 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N github.com/grafana/grafana introduced: 0 fixed: 6.0.0-beta1
MODERATE CVE-2018-18623 Tue, Jan 30

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

GHSA-cmq2-j8v8-2q44 CVE-2018-18623 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N github.com/grafana/grafana introduced: 0 fixed: 6.0.0-beta1