See how grafana compares to other vendors in security performance
An authentication bypass was found in grafana. An attacker on the network is able to view and delete snapshots by accessing a literal path.
A cross-site scripting (XSS) vulnerability exists in Grafana caused by client path traversal and open redirect. This allows attackers to redirect users to malicious websites that execute arbitrary JavaScript through custom frontend plugins. This vulnerability does not require editor permissions (as many other XSS usually does). If anonymous access is enabled, the XSS will work.This can be abused as a full read SSRF if the Grafana Image Renderer plugin is installed.
Grafana contains a path traversal vulnerability that could allow access to local files.