<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:28:53.599262+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-00493</id>
    <title>bdu:2023-00493</title>
    <updated>2026-10-05T22:28:53.629221+00:00</updated>
    <content>bdu:2023-00493</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-00493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2021-43798</id>
    <title>BIT-grafana-2021-43798 — Grafana path traversal</title>
    <updated>2026-10-05T22:28:53.629273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&lt;grafana_host_url&gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2021-43798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255903</id>
    <title>EUVD-2026-255903</title>
    <updated>2026-10-05T22:28:53.629312+00:00</updated>
    <content>EUVD-2026-255903</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43798</id>
    <title>fkie_cve-2021-43798</title>
    <updated>2026-10-05T22:28:53.629327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&lt;grafana_host_url&gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8pjx-jj86-j47p</id>
    <title>GHSA-8pjx-jj86-j47p — Grafana path traversal</title>
    <updated>2026-10-05T22:28:53.629354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Today we are releasing Grafana 8.3.1, 8.2.7, 8.1.8, 8.0.7. This patch release includes a high severity security fix that affects Grafana versions from v8.0.0-beta1 through v8.3.0.</p>
<p>Release v8.3.1, only containing a security fix:</p>
<p>- [Download Grafana 8.3.1](https://grafana.com/grafana/download/8.3.1)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-1/)</p>
<p>Release v8.2.7, only containing a security fix:</p>
<p>- [Download Grafana 8.2.7](https://grafana.com/grafana/download/8.2.7)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-2-7/)</p>
<p>Release v8.1.8, only containing a security fix:</p>
<p>- [Download Grafana 8.1.8](https://grafana.com/grafana/download/8.1.8)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-1-8/)</p>
<p>Release v8.0.7, only containing a security fix:</p>
<p>- [Download Grafana 8.0.7](https://grafana.com/grafana/download/8.0.7)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-0-7/)</p>
<p>## Path Traversal ([CVE-2021-43798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43798))</p>
<p>### Summary</p>
<p>On 2021-12-03, we received a report that Grafana is vulnerable to directory traversal, allowing access to local files. We have confirmed this for versions 8.0.0-beta1 to 8.3.0. Thanks to our defense-in-depth approach, at no time has [Grafana Cloud](https://grafana.com/cloud) been vulnerable.</p>
<p>The vulnerable URL path is: &lt;grafana_host_url&gt;/p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8pjx-jj86-j47p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43798</id>
    <title>gsd-2021-43798</title>
    <updated>2026-10-05T22:28:53.629459+00:00</updated>
    <content>gsd-2021-43798</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11816-1</id>
    <title>openSUSE-SU-2024:11816-1 — grafana-8.3.4-1.1 on GA media</title>
    <updated>2026-10-05T22:28:53.629473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-8.3.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11816-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</id>
    <title>SUSE-FU-2022:1419-1 — Feature update for grafana</title>
    <updated>2026-10-05T22:28:53.629495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Feature update for grafana</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43798</id>
    <title>Withdrawn: UBUNTU-CVE-2021-43798</title>
    <updated>2026-10-05T22:28:53.629516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&lt;grafana_host_url&gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43798"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0404</id>
    <title>WID-SEC-W-2022-0404 — Grafana: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-05T22:28:53.629539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0404"/>
  </entry>
</feed>
