VYPR

apk package

chainguard/sourcegraph-grafana

pkg:apk/chainguard/sourcegraph-grafana

Vulnerabilities (2)

  • CVE-2023-3128Jun 22, 2023
    affected < 0fixed 0

    Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

  • CVE-2023-2801Jun 6, 2023
    affected < 0fixed 0

    Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the