cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2022-44643,https://securityvulnerability.io/vulnerability/CVE-2022-44643,Access policy with access to all tenants and using label selectors has more access,"A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Grafana Labs Grafana Enterprise Metrics GEM 1.X versions prior to 1.7.1 on AMD64; GEM 2.X versions prior to 2.3.1 on AMD64.",Grafana,Enterprise Metrics,5.7,MEDIUM,0.0008699999889358878,false,,false,false,true,2024-09-16T21:20:08.000Z,,false,false,,2022-12-20T00:00:00.000Z,0 CVE-2021-31231,https://securityvulnerability.io/vulnerability/CVE-2021-31231,Local File Disclosure Vulnerability in Grafana Enterprise Metrics,"The Alertmanager component in Grafana Enterprise Metrics versions prior to 1.2.1 is susceptible to local file disclosure. This vulnerability can be exploited when the experimental.alertmanager.enable-api feature is enabled. An attacker could leverage this flaw to access sensitive file content by using the HTTP basic authentication password_file as an attack vector, as well as through alertmanager templates that can reference any specified text file. It is crucial for organizations using affected versions to take immediate action to secure their deployments and patch to the latest version.",Grafana,Enterprise Metrics,5.5,MEDIUM,0.00046999999904073775,false,,false,false,false,,,false,false,,2021-04-30T12:34:28.000Z,0