<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T10:14:02.329640+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2021-43815</id>
    <title>BIT-grafana-2021-43815 — Grafana directory traversal for `.cvs` files</title>
    <updated>2026-10-06T10:14:02.480224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in scope, and only allows access to files with the extension .csv to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Versions 8.3.2 and 7.5.12 contain a patch for this issue. There is a workaround available for users who cannot upgrade. Running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2021-43815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-100286</id>
    <title>cnvd-2021-100286</title>
    <updated>2026-10-06T10:14:02.480333+00:00</updated>
    <content>cnvd-2021-100286</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-100286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-32659</id>
    <title>EUVD-2026-32659</title>
    <updated>2026-10-06T10:14:02.480365+00:00</updated>
    <content>EUVD-2026-32659</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-32659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43815</id>
    <title>fkie_cve-2021-43815</title>
    <updated>2026-10-06T10:14:02.480387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in scope, and only allows access to files with the extension .csv to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Versions 8.3.2 and 7.5.12 contain a patch for this issue. There is a workaround available for users who cannot upgrade. Running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7533-c8qv-jm9m</id>
    <title>GHSA-7533-c8qv-jm9m — Grafana directory traversal for .cvs files</title>
    <updated>2026-10-06T10:14:02.480431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Today we are releasing Grafana `8.3.2` and `7.5.12`. This patch release includes a moderate severity security fix for directory traversal for arbitrary `.csv` files. It only affects instances that have the developer testing tool called [TestData DB data source](https://grafana.com/docs/grafana/latest/datasources/testdata/) enabled and configured.</p>
<p>The vulnerability is limited in scope, and only allows access to files with the extension `.csv` to **authenticated users only.**</p>
<p>This is a follow-up patch release to our recent [CVE-2021-43798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43798) release. If you haven’t read about that high severity security fix, we recommend that you review the [initial blog post](https://grafana.com/blog/2021/12/07/grafana-8.3.1-8.2.7-8.1.8-and-8.0.7-released-with-high-severity-security-fix/), along with our [update on the 0day](https://grafana.com/blog/2021/12/08/an-update-on-0day-cve-2021-43798-grafana-directory-traversal/).</p>
<p>Given the attention CVE-2021-43798 has brought, there’s a risk that additional researchers will find CVE-2021-43813. Out of an abundance of caution and given that both CVE-2021-43813 and CVE-2021-pending are only CVSS Score 4.3 Moderate CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N through their limited scope we are immediately releasing to the public, and on a Friday.</p>
<p>We identified several vulnerability issues in the last few weeks, and at a higher rate than in the years before. The infosec industry usually co…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7533-c8qv-jm9m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43815</id>
    <title>gsd-2021-43815</title>
    <updated>2026-10-06T10:14:02.480528+00:00</updated>
    <content>gsd-2021-43815</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13586-1</id>
    <title>openSUSE-SU-2024:13586-1 — grafana-10.1.5-2.1 on GA media</title>
    <updated>2026-10-06T10:14:02.480552+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-10.1.5-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13586-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</id>
    <title>SUSE-FU-2022:1419-1 — Feature update for grafana</title>
    <updated>2026-10-06T10:14:02.480592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Feature update for grafana</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43815</id>
    <title>UBUNTU-CVE-2021-43815</title>
    <updated>2026-10-06T10:14:02.480637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in scope, and only allows access to files with the extension .csv to authenticated users only. Grafana Cloud instances have not been affected by the vulnerability. Versions 8.3.2 and 7.5.12 contain a patch for this issue. There is a workaround available for users who cannot upgrade. Running a reverse proxy in front of Grafana that normalizes the PATH of the request will mitigate the vulnerability. The proxy will have to also be able to handle url encoded paths.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43815"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0405</id>
    <title>WID-SEC-W-2022-0405 — Grafana: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
    <updated>2026-10-06T10:14:02.480693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0405"/>
  </entry>
</feed>
