VendorsGrafanaenterprise_metricsall versions
Vulnerabilities

Grafana Labs Enterprise Metrics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-44643
Access policy with access to all tenants and using label selectors has more access
Published 2022-12-21 · Modified
8.8EPSS 0.005
CVE-2021-31231
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can be used as an attack vector to send any file content because the alertmanager can load any text file specified in the templates list.
Published 2021-04-30 · Modified
5.5EPSS 0.003