<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:35:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6420 — Moderate: grafana security and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6420</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grafana: persistent xss in grafana core plugins (CVE-2022-23552)
* grafana: plugin signature bypass (CVE-2022-31123)
* grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins (CVE-2022-31130)
* grafana: Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins (CVE-2022-39201)
* grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
* grafana: User enumeration via forget password (CVE-2022-39307)
* grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
* golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grafana: persistent xss in grafana core plugins (CVE-2022-23552)
* grafana: plugin signature bypass (CVE-2022-31123)
* grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins (CVE-2022-31130)
* grafana: Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins (CVE-2022-39201)
* grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
* grafana: User enumeration via forget password (CVE-2022-39307)
* grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
* golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6420</guid>
    </item>
    <item>
      <title>bdu:2024-02617</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02617</link>
      <description>bdu:2024-02617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02617</guid>
    </item>
    <item>
      <title>BIT-grafana-2022-39306 — Grafana contains Improper Input Validation</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2022-39306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2022-39306</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1006 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer une atteinte…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1006</link>
      <description>certfr-2022-avi-1006</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1006</guid>
    </item>
    <item>
      <title>EUVD-2026-266774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266774</link>
      <description>EUVD-2026-266774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266774</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39306</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39306</link>
      <description>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39306</guid>
    </item>
    <item>
      <title>GHSA-2x6g-h2hg-rq84 — Grafana Email addresses and usernames can not be trusted</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2x6g-h2hg-rq84</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes moderate severity security fixes for CVE-2022-39306.&lt;/p&gt;
&lt;p&gt;We are also releasing security patches for Grafana 8.5.15 to fix these issues.&lt;/p&gt;
&lt;p&gt;Release 9.2.4, latest patch, also containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.2.4](https://grafana.com/grafana/download/9.2.4)&lt;/p&gt;
&lt;p&gt;Release 8.5.15, only containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.5.15](https://grafana.com/grafana/download/8.5.15)&lt;/p&gt;
&lt;p&gt;Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering.&lt;/p&gt;
&lt;p&gt;## Privilege escalation&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. 
When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. 
The CVSS score for this vulnerability is [6.4 Moderate](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N&amp;amp;version=3.1)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Vulnerability make…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes moderate severity security fixes for CVE-2022-39306.&lt;/p&gt;
&lt;p&gt;We are also releasing security patches for Grafana 8.5.15 to fix these issues.&lt;/p&gt;
&lt;p&gt;Release 9.2.4, latest patch, also containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.2.4](https://grafana.com/grafana/download/9.2.4)&lt;/p&gt;
&lt;p&gt;Release 8.5.15, only containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.5.15](https://grafana.com/grafana/download/8.5.15)&lt;/p&gt;
&lt;p&gt;Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering.&lt;/p&gt;
&lt;p&gt;## Privilege escalation&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. 
When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. 
The CVSS score for this vulnerability is [6.4 Moderate](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N&amp;amp;version=3.1)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Vulnerability make…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2x6g-h2hg-rq84</guid>
    </item>
    <item>
      <title>gsd-2022-39306</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39306</link>
      <description>gsd-2022-39306</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39306</guid>
    </item>
    <item>
      <title>OESA-2025-1186 — grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1186</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp;amp; OpenTSDB.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.(CVE-2022-31097)&lt;/p&gt;
&lt;p&gt;Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.(CVE-2022-31123)&lt;/p&gt;
&lt;p&gt;Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user&amp;amp;apos;s Grafana…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp;amp; OpenTSDB.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.(CVE-2022-31097)&lt;/p&gt;
&lt;p&gt;Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.(CVE-2022-31123)&lt;/p&gt;
&lt;p&gt;Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user&amp;amp;apos;s Grafana…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1186</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12564-1 — grafana-8.5.15-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12564-1</link>
      <description>&lt;p&gt;grafana-8.5.15-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana-8.5.15-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12564-1</guid>
    </item>
    <item>
      <title>RHSA-2023:3642 — Red Hat Security Advisory: Red Hat Ceph Storage 6.1 Container security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3642</link>
      <description>&lt;p&gt;ramda: prototype poisoning eventsource: Exposure of Sensitive Information golang: net/http: improper sanitization of Transfer-Encoding header golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters marked: regular expression block.def may lead Denial of Service marked: regular expression inline.reflinkSearch may lead Denial of Service grafana: Use of Cache Containing Sensitive Information golang: encoding/pem: fix stack overflow in Decode Moment.js: Path traversal  in moment.locale grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix golang: net/http: handle server errors after sending GOAWAY golang: encoding/xml: stack exhaustion in Decoder.Skip golang: crypto/elliptic: panic caused by oversized scalar golang: syscall: faccessat checks wrong group golang: crypto/tls: session tickets lack random ticket_age_add golang: io/fs: stack exhaustion in Glob golang: compress/gzip: stack exhaustion in Reader.Read golang: path/filepath: stack exhaustion in Glob golang: encoding/xml: stack exhaustion in Unmarshal golang: encoding/gob: stack exhaustion in Decoder.Decode grafana: stored XSS vulnerability grafana: OAuth account takeover grafana: plugin signature bypass grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: math/big: decoding big.Float and big.Rat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ramda: prototype poisoning eventsource: Exposure of Sensitive Information golang: net/http: improper sanitization of Transfer-Encoding header golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters marked: regular expression block.def may lead Denial of Service marked: regular expression inline.reflinkSearch may lead Denial of Service grafana: Use of Cache Containing Sensitive Information golang: encoding/pem: fix stack overflow in Decode Moment.js: Path traversal  in moment.locale grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix golang: net/http: handle server errors after sending GOAWAY golang: encoding/xml: stack exhaustion in Decoder.Skip golang: crypto/elliptic: panic caused by oversized scalar golang: syscall: faccessat checks wrong group golang: crypto/tls: session tickets lack random ticket_age_add golang: io/fs: stack exhaustion in Glob golang: compress/gzip: stack exhaustion in Reader.Read golang: path/filepath: stack exhaustion in Glob golang: encoding/xml: stack exhaustion in Unmarshal golang: encoding/gob: stack exhaustion in Decoder.Decode grafana: stored XSS vulnerability grafana: OAuth account takeover grafana: plugin signature bypass grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: math/big: decoding big.Float and big.Rat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3642</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0352-1 — Security update for SUSE Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0352-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0352-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-39306</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39306</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39306</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0334 — Grafana: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0334</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Benutzerrechte zu erlangen, seine Privilegien zu erweitern und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Benutzerrechte zu erlangen, seine Privilegien zu erweitern und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0334</guid>
    </item>
  </channel>
</rss>
