CVE-2023-2801High· 7.5▾ TwilightGrafana Missing Synchronization vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Grafana is an open-source platform for monitoring and observability.
Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance.
The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly.
This might enable malicious users to crash Grafana instances through that endpoint.
Users may upgrade to version 9.4.12 and 9.5.3 to receive a fix.
github.com/grafana/grafana < 9.4.12github.com/grafana/grafana >= 9.5.0, < 9.5.3Upgrade to a patched release:
github.com/grafana/grafana 9.4.12github.com/grafana/grafana 9.5.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org
CVE-2019-19499Medium· 6.5Grafana Arbitrary File Read
CVE-2025-3415Medium· 4.3Grafana's insecure DingDing Alert integration exposes sensitive information
CVE-2020-12458Medium· 5.5Grafana information disclosure