VYPR

Bitnami package

grafana

pkg:bitnami/grafana

Vulnerabilities (105)

  • CVE-2020-13430MedMay 24, 2020
    affected < 7.0.0fixed 7.0.0

    Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

  • CVE-2020-12459MedApr 29, 2020
    affected >= 6.0.0, < 6.3.7fixed 6.3.7

    In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.

  • CVE-2020-12458MedApr 29, 2020
    affected < 6.7.4fixed 6.7.4

    An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).

  • CVE-2020-12052MedApr 27, 2020
    affected < 6.7.3fixed 6.7.3

    Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

  • CVE-2020-12245MedApr 24, 2020
    affected < 6.7.3fixed 6.7.3

    Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.

Page 6 of 6