Known vulnerabilities in grafana (Red Hat package) - page 4

Software CPE: cpe:2.3:o:red_hat:grafana_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 92
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting grafana (Red Hat package) grafana (Red Hat package) is affected by 92 known vulnerabilities: 6 high, 69 medium, 17 low Critical High Medium Low

Vulnerabilities (92)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68860 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31163
CWE-22 Medium
No
No
5.2.4-6.el7rhgs 31.10.2022 SB2022103147
SB2022103161
SB2022072942
and 6 more
#VU68557 - Authentication Bypass Using an Alternate Path or Channel
CVE-2022-35957
CWE-288 Low
No
No
9.0.9-2.el9 20.10.2022 SB2022092614
SB2022102094
SB2023050969
and 16 more
#VU66868 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23648
CWE-79 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 30.08.2022 SB2022083037
SB2022083038
SB2022110844
and 6 more
#VU66070 - Resource exhaustion
CVE-2022-30633
CWE-400 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 72 more
#VU66069 - Resource exhaustion
CVE-2022-28131
CWE-400 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 72 more
#VU66068 - Resource exhaustion
CVE-2022-30635
CWE-400 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66067 - Resource exhaustion
CVE-2022-30632
CWE-400 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 79 more
#VU66066 - Security Features
CVE-2022-32148
CWE-254 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66065 - Resource exhaustion
CVE-2022-1962
CWE-400 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 73 more
#VU66064 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-1705
CWE-444 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66062 - Resource exhaustion
CVE-2022-30631
CWE-400 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 100 more
#VU65835 - Incorrect Regular Expression
CVE-2022-31129
CWE-185 Medium
No
No
5.2.4-6.el7rhgs 27.07.2022 SB2022072729
SB2022072901
SB2022081048
and 102 more
#VU64863 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-30123
CWE-78 High
No
No
5.2.4-6.el7rhgs 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 14 more
#VU64862 - Improper input validation
CVE-2022-30122
CWE-20 Medium
No
No
5.2.4-6.el7rhgs 02.07.2022 SB2022070222
SB2022070430
SB2022072530
and 8 more
#VU64402 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21673
CWE-200 Low
No
No
7.5.15-3.el8, 7.5.15-3.el9 15.06.2022 SB2022061623
SB2022062026
SB2022081215
and 12 more
#VU64399 - Cross-Site Request Forgery (CSRF)
CVE-2022-21703
CWE-352 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
7.5.15-3.el8, 7.5.15-3.el9 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64394 - Authorization Bypass Through User-Controlled Key
CVE-2022-21713
CWE-639 Low
No
No
7.5.15-3.el8, 7.5.15-3.el9 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 13 more
#VU61798 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24790
CWE-444 Medium
No
No
5.2.4-6.el7rhgs 01.04.2022 SB2022040112
SB2022052603
SB2022092241
and 12 more
#VU61599 - Improper input validation
CVE-2022-21698
CWE-20 Medium
No
No
7.5.15-3.el8, 7.5.15-3.el9 24.03.2022 SB2022021530
SB2022032413
SB2022040807
and 110 more


Showing elements 61 - 80 out of 92