Impact
This vulnerability allows a user to retrieve annotations that exist outside the enforced time window of a public dashboard. Because the annotation timerange was not limited to the dashboard’s locked range, an attacker can read the full history of annotations that would otherwise be limited by the dashboard’s time lock. The impact is that sensitive information that the dashboard owner chose to keep hidden within a narrower time frame may be exposed to any viewer who is granted access to the public dashboard. This is an information‑disclosure flaw classified under CWE‑200.
Affected Systems
Grafana (grafana/grafana) and Grafana Enterprise (grafana/grafana-enterprise) installations with versions including 11.6.10, 12.1.6, 12.2.4, 12.3.2, and all earlier builds affected by the CVE. Users should verify the exact Grafana version in use against the vendor release notes.
Risk and Exploitability
The vulnerability scores a CVSS of 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by accessing a public dashboard that has annotations enabled and may query the annotation API to retrieve annotations outside the locked timerange. No authentication is required beyond the typical public‑dashboard access, so any user who can view the dashboard could potentially read the broader annotation history.
OpenCVE Enrichment