Grafana是Grafana开源的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana存在安全漏洞,该漏洞源于公共仪表板中启用的注释未将其注释时间范围限制在仪表板的锁定时间范围内,可能导致读取特定仪表板上可见注释的完整历史记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | grafana/grafana | 9.3.0< 11.6.10+security-01 |
affected |
12.0.0< 12.1.6+security-01 |
affected | ||
12.2.0< 12.2.4+security-01 |
affected | ||
12.3.0< 12.3.2+security-01 |
affected | ||
| Grafana | grafana/grafana-enterprise | 9.3.0< 11.6.10+security-01 |
affected |
12.0.0< 12.1.6+security-01 |
affected | ||
12.2.0< 12.2.4+security-01 |
affected | ||
12.3.0< 12.3.2+security-01 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | grafana/grafana | 9.3.0 ~ 11.6.10+security-01 | - |
|
| Grafana | grafana/grafana-enterprise | 9.3.0 ~ 11.6.10+security-01 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet