Vulnerabilities (CVE)

Filtered by vendor Grafana
Filtered by product Agent
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41090 1 Grafana 1 Agent 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in plaintext over two endpoints: metrics instance configs defined in the base YAML file are exposed at `/-/config` and metrics instance configs defined for the scraping service are exposed at `/agent/api/v1/configs/:key`. Inline secrets will be exposed to anyone bei ...

Show More

CVE-2024-8996 2 Grafana, Microsoft 2 Agent, Windows 2024-10-01 N/A 7.8 HIGH
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2