Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Sep 15, 2022

High
CISA KEV

CVE-2021-39226

Grafana LabsGrafana

Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.

Required Action

https://grafana.com/blog/2021/10/05/grafana-7.5.11-and-8.1.6-released-with-critical-security-fix/; https://nvd.nist.gov/vuln/detail/CVE-2021-39226

Vulnerability Overview

Severity
High
CISA KEV
Yes
Ransomware
Unknown
Published
Aug 25, 2022
KEV Added
Aug 25, 2022
Due Date
Sep 15, 2022
Related Articles
0

Vendor

Grafana Labs

Grafana