Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97c5-jw9r-3fwj

Опубликовано: 22 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

EPSS

Процентиль: 99%
0.81612
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVSS3: 9.8
redhat
около 3 лет назад

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVSS3: 9.8
nvd
около 3 лет назад

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVSS3: 9.8
debian
около 3 лет назад

An issue was discovered in Grafana through 7.3.4, when integrated with ...

EPSS

Процентиль: 99%
0.81612
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-312