Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-854f-qq5q-hrcq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to later be configured by Tectonic administrators. An attacker can insert an XSS payload into the dashboards.

CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to later be configured by Tectonic administrators. An attacker can insert an XSS payload into the dashboards.

EPSS

Процентиль: 46%
0.00231
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (admin/admin) for the administrator account located at grafana-credentials secret. This occurs because CoreOS does not randomize the administrative password to later be configured by Tectonic administrators. An attacker can insert an XSS payload into the dashboards.

EPSS

Процентиль: 46%
0.00231
Низкий