CyberzSOC

Applicability
← Back to CVE-2021-43798

CVE-2021-43798

In CISA KEV Grafana Labs

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2025-11-21
33 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-09-08
13 affected 12 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-10-21
4 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (62)

Product Status Versions Remediation Source
red_hat_advanced_cluster_management_for_kubernetes_2:grafana grafana as a component of Red Hat Advanced Cluster Management for Kubernetes 2 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_ceph_storage_2:grafana grafana as a component of Red Hat Ceph Storage 2 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_ceph_storage_3:grafana grafana as a component of Red Hat Ceph Storage 3 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana grafana as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_enterprise_linux_9:grafana grafana as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_storage_3:grafana grafana as a component of Red Hat Storage 3 not affected vulnerable code not present no version stated vendor label: grafana not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-azure-monitor grafana-azure-monitor as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-azure-monitor not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-cloudwatch grafana-cloudwatch as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-cloudwatch not applicable csaf_redhat
red_hat_ceph_storage_3:grafana-container grafana-container as a component of Red Hat Ceph Storage 3 not affected vulnerable code not present no version stated vendor label: grafana-container not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-elasticsearch grafana-elasticsearch as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-elasticsearch not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-graphite grafana-graphite as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-graphite not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-influxdb grafana-influxdb as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-influxdb not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-loki grafana-loki as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-loki not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-mssql grafana-mssql as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-mssql not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-mysql grafana-mysql as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-mysql not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-opentsdb grafana-opentsdb as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-opentsdb not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-postgres grafana-postgres as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-postgres not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-prometheus grafana-prometheus as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-prometheus not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-selinux not applicable csaf_redhat
red_hat_enterprise_linux_9:grafana-selinux grafana-selinux as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: grafana-selinux not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana-stackdriver grafana-stackdriver as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana-stackdriver not applicable csaf_redhat
red_hat_ceph_storage_2:grafana.src grafana.src as a component of Red Hat Ceph Storage 2 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_ceph_storage_3:grafana.src grafana.src as a component of Red Hat Ceph Storage 3 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_enterprise_linux_8:grafana.src grafana.src as a component of Red Hat Enterprise Linux 8 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_enterprise_linux_9:grafana.src grafana.src as a component of Red Hat Enterprise Linux 9 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_storage_3:grafana.src grafana.src as a component of Red Hat Storage 3 not affected vulnerable code not present no version stated vendor label: grafana.src not applicable csaf_redhat
red_hat_openshift_container_platform_3.11:openshift3/grafana openshift3/grafana as a component of Red Hat OpenShift Container Platform 3.11 not affected vulnerable code not present openshift3/grafana not applicable csaf_redhat
red_hat_openshift_container_platform_4:openshift4/ose-grafana openshift4/ose-grafana as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present openshift4/ose-grafana not applicable csaf_redhat
red_hat_ceph_storage_4:rhceph/rhceph-4-dashboard-rhel8 rhceph/rhceph-4-dashboard-rhel8 as a component of Red Hat Ceph Storage 4 not affected vulnerable code not present rhceph/rhceph-4-dashboard-rhel8 not applicable csaf_redhat
red_hat_ceph_storage_5:rhceph/rhceph-5-dashboard-rhel8 rhceph/rhceph-5-dashboard-rhel8 as a component of Red Hat Ceph Storage 5 not affected vulnerable code not present rhceph/rhceph-5-dashboard-rhel8 not applicable csaf_redhat
openshift_service_mesh_2.0:servicemesh-grafana servicemesh-grafana as a component of OpenShift Service Mesh 2.0 not affected vulnerable code not present no version stated vendor label: servicemesh-grafana not applicable csaf_redhat
openshift_service_mesh_2.0:servicemesh-grafana-prometheus servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0 not affected vulnerable code not present no version stated vendor label: servicemesh-grafana-prometheus not applicable csaf_redhat
openshift_service_mesh_2.0:servicemesh-grafana.src servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0 not affected vulnerable code not present no version stated vendor label: servicemesh-grafana.src not applicable csaf_redhat
github.com/grafana/grafana affected >= 8.3.0, < 8.3.1 vendor fix → 8.3.1 osv GHSA-8pjx-jj86-j47p
github.com/grafana/grafana affected >= 8.2.0, < 8.2.7 vendor fix → 8.2.7 osv GHSA-8pjx-jj86-j47p
github.com/grafana/grafana affected >= 8.1.0, < 8.1.8 vendor fix → 8.1.8 osv GHSA-8pjx-jj86-j47p
github.com/grafana/grafana affected >= 8.0.0-beta1, < 8.0.7 vendor fix → 8.0.7 osv GHSA-8pjx-jj86-j47p
grafana affected >= 8.0.1, < 8.0.7 vendor fix → 8.0.7 osv BIT-grafana-2021-43798
grafana affected >= 8.1.0, < 8.1.8 vendor fix → 8.1.8 osv BIT-grafana-2021-43798
grafana affected >= 8.2.0, < 8.2.7 vendor fix → 8.2.7 osv BIT-grafana-2021-43798
grafana affected >= 8.3.0, < 8.3.1 vendor fix → 8.3.1 osv BIT-grafana-2021-43798
https://github.com/grafana/grafana affected >= 8849243d272e57fd3f7a50c0e02f6a4f00bbeb04, < 822ff7595e4a7851076d72681e98d9192361df31 vendor fix → 822ff7595e4a7851076d72681e98d9192361df31 osv
https://github.com/grafana/grafana affected >= 62e720c06ba5f26a73cdecf1dea59031046f1ac1, < 52edcff798be02905898c345399ceb0c36276e09 vendor fix → 52edcff798be02905898c345399ceb0c36276e09 osv
https://github.com/grafana/grafana affected >= d7f71e9eaec57995d4537f758e300b31650d23ee, < d2cccfe91ec24c76eb4e5de60a6e6372207d9b4e vendor fix → d2cccfe91ec24c76eb4e5de60a6e6372207d9b4e osv
https://github.com/grafana/grafana affected >= 84203aaff8b01727813044d580270f03319ca8eb, <= 914fcedb72c5e1bd6752f8f311b14df9cc7f7281 none available osv
https://github.com/grafana/grafana affected < c798c0e958d15d9cc7f27c72113d572fa58545ce vendor fix → c798c0e958d15d9cc7f27c72113d572fa58545ce osv
github.com/grafana/grafana fixed 8.3.1 vendor fix → 8.3.1 osv GHSA-8pjx-jj86-j47p
github.com/grafana/grafana fixed 8.2.7 vendor fix → 8.2.7 osv GHSA-8pjx-jj86-j47p
github.com/grafana/grafana fixed 8.1.8 vendor fix → 8.1.8 osv GHSA-8pjx-jj86-j47p
github.com/grafana/grafana fixed 8.0.7 vendor fix → 8.0.7 osv GHSA-8pjx-jj86-j47p
grafana fixed 8.0.7 vendor fix → 8.0.7 osv BIT-grafana-2021-43798
grafana fixed 8.1.8 vendor fix → 8.1.8 osv BIT-grafana-2021-43798
grafana fixed 8.2.7 vendor fix → 8.2.7 osv BIT-grafana-2021-43798
grafana fixed 8.3.1 vendor fix → 8.3.1 osv BIT-grafana-2021-43798
https://github.com/grafana/grafana fixed 822ff7595e4a7851076d72681e98d9192361df31 vendor fix → 822ff7595e4a7851076d72681e98d9192361df31 osv
https://github.com/grafana/grafana fixed 52edcff798be02905898c345399ceb0c36276e09 vendor fix → 52edcff798be02905898c345399ceb0c36276e09 osv
https://github.com/grafana/grafana fixed d2cccfe91ec24c76eb4e5de60a6e6372207d9b4e vendor fix → d2cccfe91ec24c76eb4e5de60a6e6372207d9b4e osv
https://github.com/grafana/grafana fixed c798c0e958d15d9cc7f27c72113d572fa58545ce vendor fix → c798c0e958d15d9cc7f27c72113d572fa58545ce osv
grafana/grafana grafana · grafana affected >= 8.0.0, < 8.0.7 none available cve_cna
grafana/grafana grafana · grafana affected >= 8.1.0, < 8.1.8 none available cve_cna
page 1 of 2 next →

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.