cve-2021-39226

HIGH cisa_known_exploited
Description

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

Timeline
Published
2022-08-25
Last Modified
2022-08-25
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

{
  "cvss": 0.0,
  "datePublished": "2022-08-25",
  "dateUpdated": "2022-08-25",
  "description": "Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.",
  "dueDate": "2022-09-15",
  "id": "CVE-2021-39226",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/; https://nvd.nist.gov/vuln/detail/CVE-2021-39226",
  "product": "Grafana",
  "requiredAction": "Apply updates per vendor instructions.",
  "severity": "HIGH",
  "source": "cisa_known_exploited",
  "title": "Grafana Authentication Bypass Vulnerability",
  "vendor": "Grafana Labs"
}
Enrichment data
View JSON API Download JSON