Логотип exploitDog
bind:"BDU:2024-02616" OR bind:"CVE-2022-39307"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2024-02616" OR bind:"CVE-2022-39307"

Количество 10

Количество 10

fstec логотип

BDU:2024-02616

больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-39307

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2022-39307

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-39307

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2022-39307

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3p62-42x7-gxg5

около 1 года назад

Grafana User enumeration via forget password

CVSS3: 6.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0362-1

больше 2 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0353-1

больше 2 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6420

больше 1 года назад

ELSA-2023-6420: grafana security and enhancement update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240404-01

около 1 года назад

Множественные уязвимости grafana

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02616

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-39307

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-39307

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-39307

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-39307

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 6.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-3p62-42x7-gxg5

Grafana User enumeration via forget password

CVSS3: 6.7
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2023:0362-1

Security update for grafana

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0353-1

Security update for SUSE Manager Client Tools

больше 2 лет назад
oracle-oval логотип
ELSA-2023-6420

ELSA-2023-6420: grafana security and enhancement update (MODERATE)

больше 1 года назад
redos логотип
ROS-20240404-01

Множественные уязвимости grafana

CVSS3: 9.4
около 1 года назад

Уязвимостей на страницу