Количество 76
Количество 76
GHSA-m3hq-grv6-h853
Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparseable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparseable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.
SUSE-SU-2024:0487-1
Security update for SUSE Manager Client Tools
CVE-2022-39229
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.
CVE-2022-39229
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.
CVE-2022-39229
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.
CVE-2022-39229
Grafana is an open source data visualization platform for metrics, log ...
CVE-2022-27664
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
CVE-2022-27664
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
CVE-2022-27664
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
CVE-2022-27664
CVE-2022-27664
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers ca ...
GHSA-gj7m-853r-289r
Grafana when using email as a username can block other users from signing in
BDU:2024-02618
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неправильной аутентификацией, позволяющая нарушителю блокировать попытки входа в систему
ALT-PU-2022-3295
ALT-PU-2022-3295: package `grafana` update to version 9.3.1-alt1
SUSE-SU-2022:3325-1
Security update for go1.18
RLSA-2023:2177
Moderate: grafana-pcp security and enhancement update
GHSA-69cg-p879-7622
golang.org/x/net/http2 Denial of Service vulnerability
ELSA-2023-2785
ELSA-2023-2785: grafana-pcp security update (MODERATE)
ELSA-2023-2177
ELSA-2023-2177: grafana-pcp security and enhancement update (MODERATE)
BDU:2022-05544
Уязвимость пакета net/http языка программирования Go, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-m3hq-grv6-h853 Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparseable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparseable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request's Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
SUSE-SU-2024:0487-1 Security update for SUSE Manager Client Tools | больше 2 лет назад | |||
CVE-2022-39229 Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-39229 Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-39229 Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`'s password won’t match with `user_2`'s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue. | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-39229 Grafana is an open source data visualization platform for metrics, log ... | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. | CVSS3: 6.5 | 3% Низкий | около 4 лет назад | |
CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
CVSS3: 7.5 | 3% Низкий | почти 3 года назад | ||
CVE-2022-27664 In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers ca ... | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-gj7m-853r-289r Grafana when using email as a username can block other users from signing in | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
BDU:2024-02618 Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неправильной аутентификацией, позволяющая нарушителю блокировать попытки входа в систему | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
ALT-PU-2022-3295 ALT-PU-2022-3295: package `grafana` update to version 9.3.1-alt1 | CVSS3: 9.8 | почти 4 года назад | ||
SUSE-SU-2022:3325-1 Security update for go1.18 | 3% Низкий | около 4 лет назад | ||
RLSA-2023:2177 Moderate: grafana-pcp security and enhancement update | 3% Низкий | 4 месяца назад | ||
GHSA-69cg-p879-7622 golang.org/x/net/http2 Denial of Service vulnerability | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
ELSA-2023-2785 ELSA-2023-2785: grafana-pcp security update (MODERATE) | 3% Низкий | больше 3 лет назад | ||
ELSA-2023-2177 ELSA-2023-2177: grafana-pcp security and enhancement update (MODERATE) | 3% Низкий | больше 3 лет назад | ||
BDU:2022-05544 Уязвимость пакета net/http языка программирования Go, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 9.8 | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу