<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:25:04 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-01019</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01019</link>
      <description>bdu:2023-01019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01019</guid>
    </item>
    <item>
      <title>BIT-grafana-2021-39226 — Snapshot authentication bypass in grafana</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2021-39226</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot &amp;#34;public_mode&amp;#34; setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot &amp;#34;public_mode&amp;#34; setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2021-39226</guid>
    </item>
    <item>
      <title>EUVD-2026-255925</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255925</link>
      <description>EUVD-2026-255925</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255925</guid>
    </item>
    <item>
      <title>fkie_cve-2021-39226</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39226</link>
      <description>&lt;p&gt;Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot &amp;#34;public_mode&amp;#34; setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot &amp;#34;public_mode&amp;#34; setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-39226</guid>
    </item>
    <item>
      <title>GHSA-69j6-29vr-p3j9 — Authentication bypass for viewing and deletions of snapshots</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-69j6-29vr-p3j9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 7.5.11, and 8.1.6. These patch releases include an important security fix for an issue that affects all Grafana versions from 2.0.1.&lt;/p&gt;
&lt;p&gt;[Grafana Cloud](https://grafana.com/cloud) instances have already been patched and an audit did not find any usage of this attack vector. [Grafana Enterprise](https://grafana.com/products/enterprise) customers were provided with updated binaries under embargo.&lt;/p&gt;
&lt;p&gt;8.1.5 contained a single fix for bar chart panels. We believe that users can expedite deployment by moving from 8.1.4 to 8.1.6 directly.&lt;/p&gt;
&lt;p&gt;## CVE-2021-39226 Snapshot authentication bypass&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;CVSS Score: 9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&lt;/p&gt;
&lt;p&gt;We received a security report to [security@grafana.com](mailto:security@grafana.com) on 2021-09-15 about a vulnerability in Grafana regarding the snapshot feature. It was later identified as affecting Grafana versions from 2.0.1 to 8.1.6. [CVE-2021-39226](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39226) has been assigned to this vulnerability.&lt;/p&gt;
&lt;p&gt;### Impact
Unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths:&lt;/p&gt;
&lt;p&gt;* `/dashboard/snapshot/:key`, or
* `/api/snapshots/:key`&lt;/p&gt;
&lt;p&gt;If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path:&lt;/p&gt;
&lt;p&gt;* `/api/snapshots-delete/:deleteK…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 7.5.11, and 8.1.6. These patch releases include an important security fix for an issue that affects all Grafana versions from 2.0.1.&lt;/p&gt;
&lt;p&gt;[Grafana Cloud](https://grafana.com/cloud) instances have already been patched and an audit did not find any usage of this attack vector. [Grafana Enterprise](https://grafana.com/products/enterprise) customers were provided with updated binaries under embargo.&lt;/p&gt;
&lt;p&gt;8.1.5 contained a single fix for bar chart panels. We believe that users can expedite deployment by moving from 8.1.4 to 8.1.6 directly.&lt;/p&gt;
&lt;p&gt;## CVE-2021-39226 Snapshot authentication bypass&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;CVSS Score: 9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&lt;/p&gt;
&lt;p&gt;We received a security report to [security@grafana.com](mailto:security@grafana.com) on 2021-09-15 about a vulnerability in Grafana regarding the snapshot feature. It was later identified as affecting Grafana versions from 2.0.1 to 8.1.6. [CVE-2021-39226](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39226) has been assigned to this vulnerability.&lt;/p&gt;
&lt;p&gt;### Impact
Unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths:&lt;/p&gt;
&lt;p&gt;* `/dashboard/snapshot/:key`, or
* `/api/snapshots/:key`&lt;/p&gt;
&lt;p&gt;If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path:&lt;/p&gt;
&lt;p&gt;* `/api/snapshots-delete/:deleteK…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-69j6-29vr-p3j9</guid>
    </item>
    <item>
      <title>gsd-2021-39226</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-39226</link>
      <description>gsd-2021-39226</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-39226</guid>
    </item>
    <item>
      <title>OESA-2021-1445 — grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1445</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: grafana, openEuler:20.03-LTS-SP2: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp; OpenTSDB.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.(CVE-2020-24303)&#13;
&#13;
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-27846)&#13;
&#13;
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.(CVE-2021-27358)&#13;
&#13;
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.(CVE-2021-28148)&#13;
&#13;
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn&amp;amp;apos;t s…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: grafana, openEuler:20.03-LTS-SP2: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp; OpenTSDB.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.(CVE-2020-24303)&#13;
&#13;
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-27846)&#13;
&#13;
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.(CVE-2021-27358)&#13;
&#13;
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.(CVE-2021-28148)&#13;
&#13;
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn&amp;amp;apos;t s…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1445</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:0140-1 — Security update for grafana</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0140-1</link>
      <description>&lt;p&gt;Security update for grafana&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grafana&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:0140-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3769 — Red Hat Security Advisory: grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3769</link>
      <description>&lt;p&gt;grafana: Snapshot authentication bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana: Snapshot authentication bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3769</guid>
    </item>
    <item>
      <title>SUSE-FU-2022:1419-1 — Feature update for grafana</title>
      <link>https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</link>
      <description>&lt;p&gt;Feature update for grafana&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Feature update for grafana&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-39226</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39226</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot &amp;#34;public_mode&amp;#34; setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot &amp;#34;public_mode&amp;#34; configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot &amp;#34;public_mode&amp;#34; setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths: /api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key. They have no normal function and can be disabled without side effects.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39226</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0401 — Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0401</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0401</guid>
    </item>
  </channel>
</rss>
