Логотип exploitDog
bind:"BDU:2024-02619" OR bind:"CVE-2022-39201"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2024-02619" OR bind:"CVE-2022-39201"

Количество 10

Количество 10

fstec логотип

BDU:2024-02619

больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.2
EPSS: Низкий
ubuntu логотип

CVE-2022-39201

больше 2 лет назад

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2022-39201

больше 2 лет назад

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2022-39201

больше 2 лет назад

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2022-39201

больше 2 лет назад

Grafana is an open source observability and data visualization platfor ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-x744-mm8v-vpgr

около 1 года назад

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0362-1

больше 2 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0353-1

больше 2 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6420

больше 1 года назад

ELSA-2023-6420: grafana security and enhancement update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240404-01

около 1 года назад

Множественные уязвимости grafana

CVSS3: 9.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02619

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2022-39201

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-39201

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-39201

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-39201

Grafana is an open source observability and data visualization platfor ...

CVSS3: 6.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x744-mm8v-vpgr

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2023:0362-1

Security update for grafana

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0353-1

Security update for SUSE Manager Client Tools

больше 2 лет назад
oracle-oval логотип
ELSA-2023-6420

ELSA-2023-6420: grafana security and enhancement update (MODERATE)

больше 1 года назад
redos логотип
ROS-20240404-01

Множественные уязвимости grafana

CVSS3: 9.4
около 1 года назад

Уязвимостей на страницу