Bitnami package
grafana
pkg:bitnami/grafana
Vulnerabilities (105)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-13430 | Med | 6.1 | < 7.0.0 | 7.0.0 | May 24, 2020 | Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | |
| CVE-2020-12459 | Med | 5.5 | >= 6.0.0, < 6.3.7 | 6.3.7 | Apr 29, 2020 | In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable. | |
| CVE-2020-12458 | Med | 5.5 | < 6.7.4 | 6.7.4 | Apr 29, 2020 | An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords). | |
| CVE-2020-12052 | Med | 6.1 | < 6.7.3 | 6.7.3 | Apr 27, 2020 | Grafana version < 6.7.3 is vulnerable for annotation popup XSS. | |
| CVE-2020-12245 | Med | 6.1 | < 6.7.3 | 6.7.3 | Apr 24, 2020 | Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. |
- affected < 7.0.0fixed 7.0.0
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
- affected >= 6.0.0, < 6.3.7fixed 6.3.7
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
- affected < 6.7.4fixed 6.7.4
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
- affected < 6.7.3fixed 6.7.3
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
- affected < 6.7.3fixed 6.7.3
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
Page 6 of 6