grafana13.2

Direct Vulnerabilities

Known vulnerabilities in the grafana13.2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Uncaught Exception

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Cross-site Scripting (XSS)

*
  • M
Incorrect Authorization

*
  • M
Authorization Bypass Through User-Controlled Key

<0:13.2.1-0.8.hum1
  • M
Link Following

*
  • M
Unchecked Input for Loop Condition

*
  • M
Function Call with Incorrectly Specified Arguments

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Inefficient Regular Expression Complexity

*
  • H
Incorrectly Specified Destination in a Communication Channel

*
  • M
External Initialization of Trusted Variables or Data Stores

*
  • M
Incomplete Blacklist

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Improper Validation of Specified Type of Input

*
  • M
Server-Side Request Forgery (SSRF)

*
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Comparison of Incompatible Types

*
  • M
Server-Side Request Forgery (SSRF)

*
  • H
Uncaught Exception

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Incomplete Blacklist

*
  • H
Inefficient Regular Expression Complexity

*
  • H
Inefficient Regular Expression Complexity

*
  • H
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.5.hum1
  • H
Improper Validation of Specified Index, Position, or Offset in Input

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Inefficient Regular Expression Complexity

<0:13.2.1-0.5.hum1
  • M
Cross-site Scripting (XSS)

<0:13.2.1-0.7.hum1
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Information Exposure Through Caching

*
  • M
Information Exposure Through Caching

*
  • M
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.5.hum1
  • M
Privilege Defined With Unsafe Actions

<0:13.2.1-0.5.hum1
  • M
Authorization Bypass Through User-Controlled Key

<0:13.2.1-0.5.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.5.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.5.hum1
  • M
Use of a Non-reentrant Function in a Concurrent Context

<0:13.2.1-0.5.hum1
  • M
Least Privilege Violation

<0:13.2.1-0.5.hum1
  • M
Insufficient Granularity of Access Control

<0:13.2.1-0.5.hum1
  • M
Permissive Whitelist

<0:13.2.1-0.5.hum1
  • M
SQL Injection

<0:13.2.1-0.5.hum1
  • M
Improper Certificate Validation

<0:13.2.1-0.5.hum1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:13.2.1-0.5.hum1
  • M
Cross-site Scripting (XSS)

<0:13.2.1-0.6.hum1
  • M
Operator Precedence Logic Error

<0:13.2.1-0.4.hum1
  • M
Directory Traversal

<0:13.2.1-0.4.hum1
  • H
Cross-site Scripting (XSS)

<0:13.2.1-0.4.hum1
  • M
Improper Handling of Case Sensitivity

<0:13.2.1-0.7.hum1
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0:13.2.1-0.4.hum1
  • M
Cross-site Scripting (XSS)

<0:13.2.1-0.1.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.1.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.1.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.1.hum1
  • H
Authorization Bypass Through User-Controlled Key

<0:13.2.1-0.1.hum1
  • H
Improper Validation of Specified Type of Input

<0:13.2.1-0.1.hum1
  • H
Improper Validation of Unsafe Equivalence in Input

<0:13.2.1-0.2.hum1
  • H
Improper Neutralization

<0:13.2.1-0.2.hum1
  • L
Allocation of Resources Without Limits or Throttling

<0:13.2.1-0.1.hum1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:13.2.0-0.1.4.hum1
  • H
Missing Authentication for Critical Function

<0:13.2.0-0.1.1.hum1
  • H
HTTP Request Smuggling

<0:13.2.0-0.1.2.hum1
  • H
Improper Neutralization of Equivalent Special Elements

<0:13.2.0-0.1.2.hum1
  • H
Server-Side Request Forgery (SSRF)

<0:13.2.0-0.1.2.hum1
  • H
Improper Neutralization

<0:13.2.0-0.1.2.hum1
  • H
Numeric Range Comparison Without Minimum Check

<0:13.2.0-0.1.1.hum1