When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards.
No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Vulnerable Products 5
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Grafana Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
— |
9.3.0
|
|
Grafana Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
11.6.14
|
12.0.0
|
|
Grafana Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
12.1.10
|
12.2.0
|
|
Grafana Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
12.2.8
|
12.3.0
|
|
Grafana Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
|
12.3.6
|
12.4.0
|