Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39328

Опубликовано: 08 нояб. 2022
Источник: nvd
CVSS3: 9.8
CVSS3: 8.1
EPSS Низкий

Описание

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Версия от 9.2.0 (включая) до 9.2.4 (исключая)

EPSS

Процентиль: 87%
0.03732
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-362
CWE-362

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.

CVSS3: 8.1
redhat
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.

CVSS3: 9.8
debian
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. V ...

CVSS3: 9.8
github
около 1 года назад

Grafana Race condition allowing privilege escalation

CVSS3: 8.1
fstec
больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с параллельным выполнением с использованием общего ресурса с неправильной синхронизацией, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 87%
0.03732
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-362
CWE-362