VYPR

Bitnami package

grafana

pkg:bitnami/grafana

Vulnerabilities (112)

  • CVE-2025-6197MedJul 18, 2025
    affected >= 11.3.0, < 11.6.3fixed 11.6.3

    An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

  • CVE-2025-6023HigJul 18, 2025
    affected >= 11.3.0, < 11.6.3fixed 11.6.3

    An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+sec

  • CVE-2025-3415MedJul 17, 2025
    affected >= 10.4.0, < 10.4.19fixed 10.4.19

    Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+

  • CVE-2025-1088LowJun 18, 2025
    affected < 11.6.2fixed 11.6.2

    In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

  • CVE-2025-3454MedJun 2, 2025
    affected >= 10.4.0, < 10.4.17fixed 10.4.17

    This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. Th

  • CVE-2025-3260HigJun 2, 2025
    affected >= 11.6.0, < 11.6.1fixed 11.6.1

    A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless

  • CVE-2025-3580MedMay 23, 2025
    affected >= 10.4.18, < 10.4.19fixed 10.4.19

    An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organiza

  • CVE-2025-4123HigMay 22, 2025
    affected < 10.4.18fixed 10.4.18

    A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not requir

  • CVE-2025-2703MedApr 23, 2025
    affected >= 11.2.0, < 11.5.3fixed 11.5.3

    The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

  • CVE-2024-11741MedJan 31, 2025
    affected >= 10.4.0, < 10.4.15fixed 10.4.15

    Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3,  11.2.6, 11.1.11, 11.0.11 and 10.4.15

  • CVE-2024-10452LowOct 29, 2024
    affected < 10.4.13fixed 10.4.13

    Organization admins can delete pending invites created in an organization they are not part of.

  • CVE-2024-9264CriOct 18, 2024
    affected >= 11.0.0, < 11.2.2fixed 11.2.2

    The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user wit

  • CVE-2024-8118MedSep 26, 2024
    affected >= 8.5.0, < 10.4.9fixed 10.4.9

    In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

  • CVE-2024-6322MedAug 20, 2024
    affected >= 11.1.0, < 11.1.3fixed 11.1.3

    Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must

  • CVE-2024-1313MedMar 26, 2024
    affected >= 9.5.0, < 9.5.18fixed 9.5.18

    It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/ using its view key. This functionality is intended to only be available to individuals with the per

  • CVE-2024-1442MedMar 7, 2024
    affected >= 8.5.0, < 9.5.7fixed 9.5.7

    A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

  • CVE-2023-5122MedFeb 14, 2024
    affected < 0.6.13fixed 0.6.13

    Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured t

  • CVE-2023-6152MedFeb 13, 2024
    affected >= 2.5.0, < 9.5.16fixed 9.5.16

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

  • CVE-2023-4399MedOct 17, 2023
    affected >= 9.4.0, < 9.4.17fixed 9.4.17

    Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode

  • CVE-2023-4822MedOct 16, 2023
    affected >= 8.0.0, < 9.4.16fixed 9.4.16

    Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Or

Page 3 of 6