Grafana OSS是Grafana公司开源的一个可视化仪表盘。 Grafana OSS存在安全漏洞,该漏洞源于Loki datasource plugin的callResource处理程序存在路径遍历,可能导致经过身份验证的Viewer用户逃避插件的资源沙箱并访问管理端Loki端点,提取敏感后端配置和内部服务信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana OSS | 11.6.0≤ 11.6.14 |
affected |
12.2.0≤ 12.2.8 |
affected | ||
12.3.0≤ 12.3.6 |
affected | ||
12.4.0≤ 12.4.3 |
affected | ||
13.0.0≤ 13.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 11.6.0 ~ 11.6.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28381 | 9.6 CRITICAL | Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT |
| CVE-2026-42127 | 7.5 HIGH | Pre-authentication denial of service in the public dashboard query endpoint |
| CVE-2026-9029 | 7.3 HIGH | Stored XSS in the Geomap panel tile-layer attribution |
| CVE-2026-10601 | 5.4 MEDIUM | Path traversal in the Tempo and Loki data source plugins |
No comments yet