Netapp E-Series Performance Analyzer vulnerabilities

4 known vulnerabilities affecting netapp/e-series_performance_analyzer.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-21703HIGHCVSS 8.8fixed in 3.02022-02-08
CVE-2022-21703 [MEDIUM] CWE-352 CVE-2022-21703: Grafana is an open-source platform for monitoring and observability. Affected versions are subject t Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerab
nvd
CVE-2022-21702MEDIUMCVSS 5.4fixed in 3.02022-02-08
CVE-2022-21702 [MEDIUM] CWE-79 CVE-2022-21702: Grafana is an open-source platform for monitoring and observability. In affected versions an attacke Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource
nvd
CVE-2022-21713MEDIUMCVSS 4.3fixed in 3.02022-02-08
CVE-2022-21713 [MEDIUM] CWE-863 CVE-2022-21713: Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana ex Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to s
nvd
CVE-2021-28165HIGHCVSS 7.5fixed in 3.02021-04-01
CVE-2021-28165 [HIGH] CWE-400 CVE-2021-28165: In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage ca In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
nvd