Логотип exploitDog
bind: "CVE-2022-23498"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-23498"

Количество 7

Количество 7

ubuntu логотип

CVE-2022-23498

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2022-23498

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-23498

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2022-23498

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2023-01071

больше 2 лет назад

Уязвимость веб-инструмента представления данных Grafana, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить доступ к сеансу текущего пользователя

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20240403-14

около 1 года назад

Множественные уязвимости grafana

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240404-01

около 1 года назад

Множественные уязвимости grafana

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-23498

Grafana is an open-source platform for monitoring and observability. W ...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-01071

Уязвимость веб-инструмента представления данных Grafana, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить доступ к сеансу текущего пользователя

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20240403-14

Множественные уязвимости grafana

CVSS3: 7.5
около 1 года назад
redos логотип
ROS-20240404-01

Множественные уязвимости grafana

CVSS3: 9.4
около 1 года назад

Уязвимостей на страницу