Total vulnerabilities in the database
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
Software | From | Fixed in |
---|---|---|
grafana / grafana | 8.0.0 | 8.3.5 |
grafana / grafana | 3.0.0-beta1 | 3.0.0-beta1.x |
grafana / grafana | 3.0.0-beta2 | 3.0.0-beta2.x |
grafana / grafana | 3.0.0-beta3 | 3.0.0-beta3.x |
grafana / grafana | 3.0.0-beta4 | 3.0.0-beta4.x |
grafana / grafana | 3.0.0-beta5 | 3.0.0-beta5.x |
grafana / grafana | 3.0.0-beta6 | 3.0.0-beta6.x |
grafana / grafana | 3.0.0-beta7 | 3.0.0-beta7.x |
grafana / grafana | 3.0.1 | 7.5.15 |
netapp / e-series_performance_analyzer | - | 3.0 |
fedoraproject / fedora | 34 | 34.x |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
![]() |
3.0-beta1 | 7.5.15 |
![]() |
8.0.0 | 8.3.5 |