Описание
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Отчет
Grafana in the OpenShift Container Platform (OCP) and OpenShift ServiceMesh) uses oauth-proxy as an Auth Proxy, and therefore does not make use of the vulnerable SAML Authentication in the github.com/crewjam/saml module used by Grafana. Additionally, SAML is only available in the enterprise version of grafana, but as the code is still packaged, it has been marked Low impact. Red Hat Gluster Storage 3, Red Hat Ceph Storage 2, 3 and 4 ships old versions of grafana where ‘crewjam/saml’ module is not included. Therefore these products are not affected by this vulnerability. grafana as shipped with Red Hat Enterprise Linux 8 packages a vulnerable version of crewjam/saml but does not use it, as SAML is only available for the Enterprise version of grafana. For this reason, this flaw has been marked Low impact.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Service Mesh 1 | servicemesh-grafana | Out of support scope | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | ||
Red Hat 3scale API Management Platform 2 | 3scale-operator-container | Not affected | ||
Red Hat Ceph Storage 2 | grafana | Not affected | ||
Red Hat Ceph Storage 3 | grafana | Not affected | ||
Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | ||
Red Hat Enterprise Linux 9 | grafana | Not affected | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Fix deferred | ||
Red Hat Storage 3 | grafana | Not affected | ||
Red Hat Enterprise Linux 8 | grafana | Fixed | RHSA-2021:1859 | 18.05.2021 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
XML Processing error in github.com/crewjam/saml
ELSA-2021-1859: grafana security, bug fix, and enhancement update (MODERATE)
EPSS
9.8 Critical
CVSS3