Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tested state of Grafana security on v3? #5595

Closed
1 task
rayprill opened this issue Jul 15, 2016 · 1 comment
Closed
1 task

Tested state of Grafana security on v3? #5595

rayprill opened this issue Jul 15, 2016 · 1 comment

Comments

@rayprill
Copy link

  • Question

Has Grafana been tested to assure it defends against common security issues? Specifically for v3.0.4, are the following common security exploits closed?

  1. Does Grafana validate all cookies? Are all session cookies validated before granting access? Are different cookies used pre and post authentication?
  2. Does Grafana defend against clickjacking? Can it be loaded in another application’s iframe?
  3. Does Grafana disable auto-complete for the login screen?
  4. Does Grafana defend against Cross-site scripting?
  5. Does Grafana defend against Script injection?
@nopzor1200
Copy link
Contributor

Hello,

The answers to these questions get quite varied. This is something we are starting to pay more attention to. We are also in the beginning processes of doing ongoing third party testing.

For customers with support subscriptions for Grafana, we do provide additional assurances, and are sharing the results of some of the aformentioned third party testing, etc.

However, for purposes if this Github issue, no, Grafana makes no assurances and provides no warranties.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants