Описание
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running git remote get-url origin
.
If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.
A flaw was found in grafana-plugin-sdk-go package. The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running git remote get-url origin
. If credentials are included in the repository URI, for example, to allow for fetching of private dependencies, the final binary will contain the full URI, including said credentials.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Fix deferred | ||
Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Out of support scope | ||
Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Out of support scope | ||
Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Out of support scope | ||
Red Hat Enterprise Linux 8 | grafana | Will not fix | ||
Red Hat Enterprise Linux 8 | grafana-pcp | Will not fix | ||
Red Hat Enterprise Linux 9 | grafana | Will not fix | ||
Red Hat Enterprise Linux 9 | grafana-pcp | Will not fix |
Показывать по
Дополнительная информация
Статус:
5.5 Medium
CVSS3
Связанные уязвимости
The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.
Уязвимость SDK-плагина платформы для мониторинга и наблюдения Grafana, связанная с передачей токенов аутентификации некоторым целевым плагинам, позволяющая нарушителю получить доступ к учётным данным репозитория
5.5 Medium
CVSS3