VYPR

Grafana Enterprise

by Grafana

Source repositories

CVEs (23)

  • CVE-2022-28660CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

  • CVE-2023-3128CriJun 22, 2023
    risk 0.61cvss 9.4epss 0.04

    Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

  • CVE-2025-41115CriNov 21, 2025
    risk 0.59cvss 10.0epss 0.17

    SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a…

  • CVE-2022-24812HigApr 12, 2022
    risk 0.52cvss 8.0epss 0.02

    Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the…

  • CVE-2023-2801HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at…

  • CVE-2023-0507HigMar 1, 2023
    risk 0.49cvss 7.3epss 0.15

    Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and…

  • CVE-2021-28148HigMar 22, 2021
    risk 0.49cvss 7.5epss 0.04

    One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a…

  • CVE-2023-0594HigMar 1, 2023
    risk 0.48cvss 7.3epss 0.09

    Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. The stored XSS vulnerability was possible due the value of a span's attributes/resources were not…

  • CVE-2021-27962HigMar 22, 2021
    risk 0.46cvss 7.1epss 0.02

    Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

  • CVE-2023-4822MedOct 16, 2023
    risk 0.44cvss 6.7epss 0.01

    Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer,…

  • CVE-2023-4399MedOct 17, 2023
    risk 0.43cvss 6.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used…

  • CVE-2021-28147MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.02

    The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows…

  • CVE-2021-28146MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.01

    The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to…

  • CVE-2025-41117MedFeb 12, 2026
    risk 0.37cvss 6.8epss 0.00

    Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected;…

  • CVE-2022-44643MedDec 20, 2022
    risk 0.37cvss 5.7epss 0.00

    A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector…

  • CVE-2021-31231MedApr 30, 2021
    risk 0.36cvss 5.5epss 0.00

    The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a…

  • CVE-2023-6152MedFeb 13, 2024
    risk 0.35cvss 5.4epss 0.01

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

  • CVE-2026-21722MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did…

  • CVE-2024-9476MedNov 13, 2024
    risk 0.33cvss epss 0.00

    A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who…

  • CVE-2023-1410MedMar 23, 2023
    risk 0.33cvss 6.2epss 0.01

    Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An…

Page 1 of 2