rpm package
suse/spacewalk-client-tools&distro=SUSE Manager Client Tools 12
pkg:rpm/suse/spacewalk-client-tools&distro=SUSE%20Manager%20Client%20Tools%2012
Vulnerabilities (48)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-28146 | — | < 4.2.12-52.53.2 | 4.2.12-52.53.2 | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to gra | ||
| CVE-2021-27962 | — | < 4.2.12-52.53.2 | 4.2.12-52.53.2 | Mar 22, 2021 | Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access. | ||
| CVE-2020-7753 | — | < 4.3.18-52.95.2 | 4.3.18-52.95.2 | Oct 27, 2020 | All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim(). | ||
| CVE-2020-13379 | — | < 4.1.5-52.32.2 | 4.1.5-52.32.2 | Jun 3, 2020 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information abo | ||
| CVE-2020-12245 | — | < 4.1.5-52.32.2 | 4.1.5-52.32.2 | Apr 24, 2020 | Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. | ||
| CVE-2019-10215 | — | < 4.1.5-52.32.2 | 4.1.5-52.32.2 | Oct 8, 2019 | Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser. | ||
| CVE-2019-15043 | — | < 4.1.5-52.32.2 | 4.1.5-52.32.2 | Sep 3, 2019 | In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. | ||
| CVE-2017-7470 | — | < 2.5.13.8-48.1 | 2.5.13.8-48.1 | Jul 27, 2018 | It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py. |
- CVE-2021-28146Mar 22, 2021affected < 4.2.12-52.53.2fixed 4.2.12-52.53.2
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to gra
- CVE-2021-27962Mar 22, 2021affected < 4.2.12-52.53.2fixed 4.2.12-52.53.2
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
- CVE-2020-7753Oct 27, 2020affected < 4.3.18-52.95.2fixed 4.3.18-52.95.2
All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
- CVE-2020-13379Jun 3, 2020affected < 4.1.5-52.32.2fixed 4.1.5-52.32.2
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information abo
- CVE-2020-12245Apr 24, 2020affected < 4.1.5-52.32.2fixed 4.1.5-52.32.2
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
- CVE-2019-10215Oct 8, 2019affected < 4.1.5-52.32.2fixed 4.1.5-52.32.2
Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.
- CVE-2019-15043Sep 3, 2019affected < 4.1.5-52.32.2fixed 4.1.5-52.32.2
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
- CVE-2017-7470Jul 27, 2018affected < 2.5.13.8-48.1fixed 2.5.13.8-48.1
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
Page 3 of 3