Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39324

Опубликовано: 27 янв. 2023
Источник: nvd
CVSS3: 6.7
CVSS3: 3.5
EPSS Низкий

Описание

Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the originalUrl parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The Open original dashboard button no longer points to the to the real original dashboard but to the attacker’s injected URL. This issue is fixed in versions 8.5.16 and 9.2.8.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия до 8.5.16 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.2.8 (исключая)

EPSS

Процентиль: 34%
0.00132
Низкий

6.7 Medium

CVSS3

3.5 Low

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The `Open original dashboard` button no longer points to the to the real original dashboard but to the attacker’s injected URL. This issue is fixed in versions 8.5.16 and 9.2.8.

CVSS3: 6.7
redhat
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The `Open original dashboard` button no longer points to the to the real original dashboard but to the attacker’s injected URL. This issue is fixed in versions 8.5.16 and 9.2.8.

CVSS3: 6.7
debian
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. P ...

CVSS3: 6.7
github
около 1 года назад

Grafana Spoofing originalUrl of snapshots

CVSS3: 3.5
fstec
больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неправильной нейтрализацией ввода во время создания веб-страницы, позволяющая нарушителю внедрять введенный URL-адреса

EPSS

Процентиль: 34%
0.00132
Низкий

6.7 Medium

CVSS3

3.5 Low

CVSS3

Дефекты

CWE-79