目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

Grafana 厂商漏洞列表 / CVE 中文分析 85

Grafana 厂商相关 85 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Grafana 是开源分析与可视化平台,广泛用于监控指标与日志数据。其历史漏洞多涉及未授权访问、越权操作及跨站脚本,部分版本曾存在远程代码执行风险。近期安全更新强化了身份验证机制与插件沙箱隔离,以应对供应链攻击。鉴于已收录 85 条 CVE,用户需及时升级并配置最小权限原则,确保数据看板与后端存储的安全隔离,防范敏感信息泄露。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-21728 Tempo query limit results in unbounded memory allocation — Tempo 7.5 High2026-04-24
CVE-2026-21726 Loki Path Traversal - CVE-2021-36156 Bypass — Loki 5.3 Medium2026-04-15
CVE-2025-41118 Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection — Pyroscope 9.1 Critical2026-04-15
CVE-2026-21727 Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record — Grafana Correlations 3.3 Low2026-04-15
CVE-2025-12141 Grafana Alerting Editors can edit destination of webhooks they did not create — Grafana AlertingCWE-200 8.1 -2026-04-15
CVE-2026-27879 Query resampling can cause unbounded memory allocations — Grafana 6.5 Medium2026-03-27
CVE-2026-28375 Grafana Testdata datasource can issue unbounded memory allocations — Grafana 6.5 Medium2026-03-27
CVE-2026-27876 RCE on Grafana via sqlExpressions — Grafana 9.1 Critical2026-03-27
CVE-2026-27880 OpenFeature evaluation API reads input data with no bounds — Grafana 7.5 High2026-03-27
CVE-2026-27877 Public dashboards discloses all direct mode datasources — Grafana 6.5 Medium2026-03-27
CVE-2026-28377 S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern) — Tempo 7.5 High2026-03-26
CVE-2026-21724 Missing Protected-field Authorization in Provisioning Contact Points API — Grafana OSS 5.4 Medium2026-03-26
CVE-2026-33375 Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS — Grafana OSS 6.5 Medium2026-03-26
CVE-2026-21725 Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name — Grafana 2.6 Low2026-02-25
CVE-2025-41117 XSS in Grafana Explore stack trace — grafana/grafana 6.8 Medium2026-02-12
CVE-2026-21722 Public Dashboards time range restriction on annotations can be bypassed — grafana/grafana 5.3 Medium2026-02-12
CVE-2026-21721 Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation — grafana/grafana 8.1 High2026-01-27
CVE-2026-21720 Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out — grafana/grafana-enterprise 7.5 High2026-01-27
CVE-2025-41115 Incorrect privilege assignment — Grafana Enterprise 10.0 Critical2025-11-21
CVE-2025-11539 Arbitrary Code Execution in Grafana Image Renderer Plugin — grafana-image-rendererCWE-94 9.9 Critical2025-10-09
CVE-2025-10630 Regex DoS in Grafana Zabbix Plugin — grafana-zabbix-pluginCWE-20 4.3 Medium2025-09-19
CVE-2025-8341 SSRF in Infinity Datasource Plugin — grafana-infinity-datasourceCWE-918 5.0 Medium2025-08-04
CVE-2025-6197 Grafana OSS 安全漏洞 — GrafanaCWE-601 4.2 Medium2025-07-18
CVE-2025-6023 Grafana OSS 安全漏洞 — GrafanaCWE-601 7.6 High2025-07-18
CVE-2025-3415 Grafana 安全漏洞 — GrafanaCWE-200 4.3 Medium2025-07-17
CVE-2025-1088 Very long unicode dashboard title or panel name can hang the frontend — GrafanaCWE-20 2.7 Low2025-06-18
CVE-2025-3454 Grafana 安全漏洞 — GrafanaCWE-285 5.0 Medium2025-06-02
CVE-2025-3260 Grafana 安全漏洞 — GrafanaCWE-863 8.3 High2025-06-02
CVE-2025-3580 Grafana OSS 安全漏洞 — GrafanaCWE-284 5.5 Medium2025-05-23
CVE-2025-4123 Grafana 安全漏洞 — GrafanaCWE-79 7.6 High2025-05-22

本页汇总了 Grafana 厂商截至目前公开的全部 85 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。