Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31130

Опубликовано: 13 окт. 2022
Источник: nvd
CVSS3: 4.9
CVSS3: 7.5
EPSS Низкий

Описание

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия до 8.5.14 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.1.8 (исключая)

EPSS

Процентиль: 38%
0.00158
Низкий

4.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 2 лет назад

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.

CVSS3: 7.5
redhat
больше 2 лет назад

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.

CVSS3: 4.9
debian
больше 2 лет назад

Grafana is an open source observability and data visualization platfor ...

CVSS3: 4.9
github
около 1 года назад

Grafana Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 38%
0.00158
Низкий

4.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-200
CWE-522