Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-39307

Опубликовано: 08 нояб. 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the /api/user/password/sent-reset-email URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-loki-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Not affected
OpenShift Service Mesh 2openshift-service-mesh/grafana-rhel8Not affected
OpenShift Service Mesh 2.0openshift-service-mesh/grafana-rhel8Out of support scope
OpenShift Service Mesh 2.0servicemesh-grafanaOut of support scope
OpenShift Service Mesh 2.1openshift-service-mesh/grafana-rhel8Out of support scope
OpenShift Service Mesh 2.1servicemesh-grafanaOut of support scope
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel8Will not fix
Red Hat build of QuarkusgrafanaNot affected
Red Hat Ceph Storage 3grafanaOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-205->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2138015grafana: User enumeration via forget password

EPSS

Процентиль: 45%
0.00224
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 6.7
nvd
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 6.7
debian
больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 6.7
github
около 1 года назад

Grafana User enumeration via forget password

CVSS3: 5.3
fstec
больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 45%
0.00224
Низкий

5.3 Medium

CVSS3