CVE-2026-27877
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
Слабость
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
Затронутые продукты
- grafana grafana
Источники
- https://grafana.com/security/security-advisories/cve-2026-27877
- https://access.redhat.com/errata/RHSA-2026:10223
- https://access.redhat.com/errata/RHSA-2026:10226
- https://access.redhat.com/errata/RHSA-2026:11416
- https://access.redhat.com/errata/RHSA-2026:11417
- https://access.redhat.com/errata/RHSA-2026:19134
Найдите уязвимость раньше атакующего.
Войдите через GitHub и запустите первый аудит меньше чем за минуту. Для бесплатного тарифа банковская карта не нужна.