Логотип exploitDog
bind:CVE-2022-21713
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21713

Количество 13

Количество 13

ubuntu логотип

CVE-2022-21713

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-21713

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-21713

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-21713

больше 3 лет назад

Grafana is an open-source platform for monitoring and observability. A ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-63g3-9jq3-mccv

около 1 года назад

Grafana API IDOR

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3765-1

больше 2 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1396-1

около 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2022:1419-1

около 3 лет назад

Feature update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2134-1

почти 3 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
rocky логотип

RLSA-2022:8057

больше 2 лет назад

Important: grafana security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2022:7519

больше 2 лет назад

Moderate: grafana security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8057

больше 2 лет назад

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7519

больше 2 лет назад

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. A ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-63g3-9jq3-mccv

Grafana API IDOR

CVSS3: 4.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2022:3765-1

Security update for grafana

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2022:1396-1

Security update for SUSE Manager Client Tools

около 3 лет назад
suse-cvrf логотип
SUSE-FU-2022:1419-1

Feature update for grafana

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2134-1

Security update for SUSE Manager Client Tools

почти 3 года назад
rocky логотип
RLSA-2022:8057

Important: grafana security, bug fix, and enhancement update

больше 2 лет назад
rocky логотип
RLSA-2022:7519

Moderate: grafana security, bug fix, and enhancement update

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8057

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7519

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

больше 2 лет назад

Уязвимостей на страницу