VulnSea

storage vulnerabilities

CVEs whose affected-version data names the storage package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2024-1313Medium· 6.5
2y ago

grafana: vulnerable to authorization bypass (CVE-2024-1313)

A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…

SunlitRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.65%via CSAF
CVE-2024-1442Medium· 6.0
2y ago

grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…

SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9EPSS 0.80%via CSAF
CVE-2022-39324Medium· 6.7
3y ago

grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
CVE-2022-39307Medium· 5.3
3y ago

grafana: User enumeration via forget password (CVE-2022-39307)

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via CSAF
CVE-2022-39306High· 8.1
3y ago

grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)

An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…

TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.76%via CSAF
CVE-2022-3064High· 7.5
4y ago

go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)

A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 1.7%via CSAF
CVE-2020-14040High· 7.5
6y ago

golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vuln…

TwilightRed Hat · Red Hat OpenShift Container Platform 4.6EPSS 1.8%via CSAF
storage vulnerabilities (CVEs) · VulnSea