Логотип exploitDog
bind: "CVE-2022-23498"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-23498"

Количество 7

Количество 7

ubuntu логотип

CVE-2022-23498

около 3 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-23498

около 3 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-23498

около 3 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-23498

около 3 лет назад

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2023-01071

около 3 лет назад

Уязвимость веб-инструмента представления данных Grafana, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить доступ к сеансу текущего пользователя

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20240403-14

почти 2 года назад

Множественные уязвимости grafana

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240404-01

почти 2 года назад

Множественные уязвимости grafana

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 7.1
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-01071

Уязвимость веб-инструмента представления данных Grafana, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить доступ к сеансу текущего пользователя

CVSS3: 7.1
0%
Низкий
около 3 лет назад
redos логотип
ROS-20240403-14

Множественные уязвимости grafana

CVSS3: 7.5
почти 2 года назад
redos логотип
ROS-20240404-01

Множественные уязвимости grafana

CVSS3: 9.4
почти 2 года назад

Уязвимостей на страницу