Количество 10
Количество 10
GHSA-3p62-42x7-gxg5
Grafana User enumeration via forget password
CVE-2022-39307
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.
CVE-2022-39307
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.
CVE-2022-39307
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.
CVE-2022-39307
Grafana is an open-source platform for monitoring and observability. W ...
BDU:2024-02616
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю получить доступ к конфиденциальным данным
SUSE-SU-2023:0362-1
Security update for grafana
SUSE-SU-2023:0353-1
Security update for SUSE Manager Client Tools
ELSA-2023-6420
ELSA-2023-6420: grafana security and enhancement update (MODERATE)
ROS-20240404-01
Множественные уязвимости grafana
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
GHSA-3p62-42x7-gxg5 Grafana User enumeration via forget password  | CVSS3: 6.7  | 0% Низкий | больше 1 года назад | |
CVE-2022-39307 Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.  | CVSS3: 6.7  | 0% Низкий | почти 3 года назад | |
CVE-2022-39307 Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.  | CVSS3: 5.3  | 0% Низкий | почти 3 года назад | |
CVE-2022-39307 Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.  | CVSS3: 6.7  | 0% Низкий | почти 3 года назад | |
CVE-2022-39307 Grafana is an open-source platform for monitoring and observability. W ...  | CVSS3: 6.7  | 0% Низкий | почти 3 года назад | |
BDU:2024-02616 Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю получить доступ к конфиденциальным данным  | CVSS3: 5.3  | 0% Низкий | почти 3 года назад | |
SUSE-SU-2023:0362-1 Security update for grafana  | больше 2 лет назад | |||
SUSE-SU-2023:0353-1 Security update for SUSE Manager Client Tools  | больше 2 лет назад | |||
ELSA-2023-6420 ELSA-2023-6420: grafana security and enhancement update (MODERATE)  | почти 2 года назад | |||
ROS-20240404-01 Множественные уязвимости grafana  | CVSS3: 9.4  | больше 1 года назад | 
Уязвимостей на страницу