Логотип exploitDog
bind:CVE-2022-21673
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21673

Количество 13

Количество 13

ubuntu логотип

CVE-2022-21673

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-21673

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-21673

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-21673

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. I ...

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2024-02596

больше 3 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1396-1

около 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2022:1419-1

около 3 лет назад

Feature update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2134-1

почти 3 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
rocky логотип

RLSA-2022:8057

больше 2 лет назад

Important: grafana security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2022:7519

больше 2 лет назад

Moderate: grafana security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8057

больше 2 лет назад

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7519

больше 2 лет назад

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20240403-01

около 1 года назад

Множественные уязвимости grafana

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21673

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-21673

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-21673

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-21673

Grafana is an open-source platform for monitoring and observability. I ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2024-02596

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с раскрытием конфиденциальной информации несанкционированному субъекту, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1396-1

Security update for SUSE Manager Client Tools

около 3 лет назад
suse-cvrf логотип
SUSE-FU-2022:1419-1

Feature update for grafana

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2134-1

Security update for SUSE Manager Client Tools

почти 3 года назад
rocky логотип
RLSA-2022:8057

Important: grafana security, bug fix, and enhancement update

больше 2 лет назад
rocky логотип
RLSA-2022:7519

Moderate: grafana security, bug fix, and enhancement update

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8057

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7519

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад
redos логотип
ROS-20240403-01

Множественные уязвимости grafana

CVSS3: 9.8
около 1 года назад

Уязвимостей на страницу