Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-23498

Опубликовано: 03 фев. 2023
Источник: redhat
CVSS3: 8.8

Описание

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including grafana_session. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

A flaw was found in the Grafana package. When data-source query caching is enabled, Grafana caches all headers, including grafana_session. As a result, any user that queries a data source where the caching is enabled can acquire another user’s session.

Меры по смягчению последствий

To mitigate the vulnerability, disable the data source query caching for all data sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.1servicemesh-grafanaNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Not affected
Red Hat Ceph Storage 3grafanaNot affected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaAffected
Red Hat Storage 3grafanaNot affected
Red Hat Ceph Storage 5.3rhceph/rhceph-5-dashboard-rhel8FixedRHSA-2024:074608.02.2024
Red Hat Ceph Storage 6.1rhceph/keepalived-rhel9FixedRHSA-2023:364215.06.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2167266grafana: Use of Cache Containing Sensitive Information

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
nvd
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
debian
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 7.1
fstec
больше 2 лет назад

Уязвимость веб-инструмента представления данных Grafana, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить доступ к сеансу текущего пользователя

CVSS3: 7.5
redos
около 1 года назад

Множественные уязвимости grafana

8.8 High

CVSS3