Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31123

Опубликовано: 13 окт. 2022
Источник: nvd
CVSS3: 6.1
CVSS3: 7.8
EPSS Низкий

Описание

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 8.5.14 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.1.8 (исключая)
Конфигурация 2
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*

EPSS

Процентиль: 0%
0.00008
Низкий

6.1 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 2 лет назад

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
redhat
больше 2 лет назад

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS3: 6.1
debian
больше 2 лет назад

Grafana is an open source observability and data visualization platfor ...

CVSS3: 6.1
github
около 1 года назад

Grafana Plugin signature bypass

CVSS3: 7.8
fstec
больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неправильной проверкой криптографической подписи, позволяющая нарушителю установить вредоносное программное обеспечение на уязвимое устройство

EPSS

Процентиль: 0%
0.00008
Низкий

6.1 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-347