VYPR

Enterprise Metrics

by Grafana

CVEs (2)

  • CVE-2022-44643MedDec 20, 2022
    risk 0.37cvss 5.7epss 0.00

    A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector…

  • CVE-2021-31231MedApr 30, 2021
    risk 0.36cvss 5.5epss 0.00

    The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a…