<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 22:28:49 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-00493</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-00493</link>
      <description>bdu:2023-00493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-00493</guid>
    </item>
    <item>
      <title>BIT-grafana-2021-43798 — Grafana path traversal</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2021-43798</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&amp;lt;grafana_host_url&amp;gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&amp;lt;grafana_host_url&amp;gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2021-43798</guid>
    </item>
    <item>
      <title>EUVD-2026-255903</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-255903</link>
      <description>EUVD-2026-255903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-255903</guid>
    </item>
    <item>
      <title>fkie_cve-2021-43798</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43798</link>
      <description>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&amp;lt;grafana_host_url&amp;gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&amp;lt;grafana_host_url&amp;gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-43798</guid>
    </item>
    <item>
      <title>GHSA-8pjx-jj86-j47p — Grafana path traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8pjx-jj86-j47p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 8.3.1, 8.2.7, 8.1.8, 8.0.7. This patch release includes a high severity security fix that affects Grafana versions from v8.0.0-beta1 through v8.3.0.&lt;/p&gt;
&lt;p&gt;Release v8.3.1, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.3.1](https://grafana.com/grafana/download/8.3.1)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-1/)&lt;/p&gt;
&lt;p&gt;Release v8.2.7, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.2.7](https://grafana.com/grafana/download/8.2.7)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-2-7/)&lt;/p&gt;
&lt;p&gt;Release v8.1.8, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.1.8](https://grafana.com/grafana/download/8.1.8)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-1-8/)&lt;/p&gt;
&lt;p&gt;Release v8.0.7, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.0.7](https://grafana.com/grafana/download/8.0.7)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-0-7/)&lt;/p&gt;
&lt;p&gt;## Path Traversal ([CVE-2021-43798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43798))&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On 2021-12-03, we received a report that Grafana is vulnerable to directory traversal, allowing access to local files. We have confirmed this for versions 8.0.0-beta1 to 8.3.0. Thanks to our defense-in-depth approach, at no time has [Grafana Cloud](https://grafana.com/cloud) been vulnerable.&lt;/p&gt;
&lt;p&gt;The vulnerable URL path is: &amp;lt;grafana_host_url&amp;gt;/p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 8.3.1, 8.2.7, 8.1.8, 8.0.7. This patch release includes a high severity security fix that affects Grafana versions from v8.0.0-beta1 through v8.3.0.&lt;/p&gt;
&lt;p&gt;Release v8.3.1, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.3.1](https://grafana.com/grafana/download/8.3.1)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-1/)&lt;/p&gt;
&lt;p&gt;Release v8.2.7, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.2.7](https://grafana.com/grafana/download/8.2.7)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-2-7/)&lt;/p&gt;
&lt;p&gt;Release v8.1.8, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.1.8](https://grafana.com/grafana/download/8.1.8)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-1-8/)&lt;/p&gt;
&lt;p&gt;Release v8.0.7, only containing a security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.0.7](https://grafana.com/grafana/download/8.0.7)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-0-7/)&lt;/p&gt;
&lt;p&gt;## Path Traversal ([CVE-2021-43798](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43798))&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On 2021-12-03, we received a report that Grafana is vulnerable to directory traversal, allowing access to local files. We have confirmed this for versions 8.0.0-beta1 to 8.3.0. Thanks to our defense-in-depth approach, at no time has [Grafana Cloud](https://grafana.com/cloud) been vulnerable.&lt;/p&gt;
&lt;p&gt;The vulnerable URL path is: &amp;lt;grafana_host_url&amp;gt;/p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8pjx-jj86-j47p</guid>
    </item>
    <item>
      <title>gsd-2021-43798</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-43798</link>
      <description>gsd-2021-43798</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-43798</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11816-1 — grafana-8.3.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11816-1</link>
      <description>&lt;p&gt;grafana-8.3.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana-8.3.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11816-1</guid>
    </item>
    <item>
      <title>SUSE-FU-2022:1419-1 — Feature update for grafana</title>
      <link>https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</link>
      <description>&lt;p&gt;Feature update for grafana&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Feature update for grafana&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2021-43798</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43798</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&amp;lt;grafana_host_url&amp;gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `&amp;lt;grafana_host_url&amp;gt;/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43798</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0404 — Grafana: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0404</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0404</guid>
    </item>
  </channel>
</rss>
