SCA: security update for github.com/grafana/grafana (GHSA-69j6-29vr-p3j9)

high Tenable Cloud Security Plugin ID 411344

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Grafana is an open source data visualization platform. In affected versions unauthenticated and
authenticated users are able to view the snapshot with the lowest database key by accessing the literal
paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration
setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with
the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the
snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest
database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The
combination of deletion and viewing enables a complete walk through all snapshot data while resulting in
complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason
you cannot upgrade you can use a reverse proxy or similar to block access to the literal paths:
/api/snapshots/:key, /api/snapshots-delete/:deleteKey, /dashboard/snapshot/:key, and /api/snapshots/:key.
They have no normal function and can be disabled without side effects. (CVE-2021-39226)

See Also

https://github.com/advisories/GHSA-69j6-29vr-p3j9

Plugin Details

Severity: High

ID: 411344

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 56.93

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-39226

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/5/2021

Vulnerability Publication Date: 10/5/2021

CISA Known Exploited Vulnerability Due Dates: 9/15/2022

Reference Information

CVE: CVE-2021-39226