Логотип exploitDog
bind:"GHSA-ff5c-938w-8c9q" OR bind:"CVE-2022-35957"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-ff5c-938w-8c9q" OR bind:"CVE-2022-35957"

Количество 12

Количество 12

github логотип

GHSA-ff5c-938w-8c9q

около 1 года назад

Grafana Escalation from admin to server admin when auth proxy is used

CVSS3: 6.6
EPSS: Низкий
ubuntu логотип

CVE-2022-35957

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

CVSS3: 6.6
EPSS: Низкий
redhat логотип

CVE-2022-35957

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

CVSS3: 6.6
EPSS: Низкий
nvd логотип

CVE-2022-35957

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2022-35957

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. V ...

CVSS3: 6.6
EPSS: Низкий
fstec логотип

BDU:2024-02622

больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с обходом аутентификации путем спуфинга, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность

CVSS3: 6.6
EPSS: Низкий
oracle-oval логотип

ELSA-2023-2167

около 2 лет назад

ELSA-2023-2167: grafana security and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4437-1

больше 2 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4428-1

больше 2 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2575-1

почти 2 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2578-1

почти 2 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
redos логотип

ROS-20240404-01

около 1 года назад

Множественные уязвимости grafana

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-ff5c-938w-8c9q

Grafana Escalation from admin to server admin when auth proxy is used

CVSS3: 6.6
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2022-35957

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-35957

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-35957

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-35957

Grafana is an open-source platform for monitoring and observability. V ...

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02622

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с обходом аутентификации путем спуфинга, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность

CVSS3: 6.6
1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-2167

ELSA-2023-2167: grafana security and enhancement update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:4437-1

Security update for SUSE Manager Client Tools

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:4428-1

Security update for grafana

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2575-1

Security update for SUSE Manager Client Tools

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:2578-1

Security update for SUSE Manager Client Tools

почти 2 года назад
redos логотип
ROS-20240404-01

Множественные уязвимости grafana

CVSS3: 9.4
около 1 года назад

Уязвимостей на страницу