Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-15635

Опубликовано: 23 сент. 2019
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:grafana:grafana:5.4.0:-:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00275
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 5 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
redhat
больше 5 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
debian
больше 5 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
github
около 3 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

EPSS

Процентиль: 51%
0.00275
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-319