Логотип exploitDog
bind:CVE-2022-21713
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-21713

Количество 13

Количество 13

ubuntu логотип

CVE-2022-21713

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2022-21713

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-21713

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-21713

почти 4 года назад

Grafana is an open-source platform for monitoring and observability. A ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-63g3-9jq3-mccv

больше 1 года назад

Grafana API IDOR

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3765-1

около 3 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1396-1

больше 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2022:1419-1

больше 3 лет назад

Feature update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2134-1

больше 3 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
rocky логотип

RLSA-2022:8057

около 3 лет назад

Important: grafana security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2022:7519

около 3 лет назад

Moderate: grafana security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8057

около 3 лет назад

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7519

около 3 лет назад

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVSS3: 4.3
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-21713

Grafana is an open-source platform for monitoring and observability. A ...

CVSS3: 4.3
0%
Низкий
почти 4 года назад
github логотип
GHSA-63g3-9jq3-mccv

Grafana API IDOR

CVSS3: 4.3
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2022:3765-1

Security update for grafana

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1396-1

Security update for SUSE Manager Client Tools

больше 3 лет назад
suse-cvrf логотип
SUSE-FU-2022:1419-1

Feature update for grafana

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2134-1

Security update for SUSE Manager Client Tools

больше 3 лет назад
rocky логотип
RLSA-2022:8057

Important: grafana security, bug fix, and enhancement update

около 3 лет назад
rocky логотип
RLSA-2022:7519

Moderate: grafana security, bug fix, and enhancement update

около 3 лет назад
oracle-oval логотип
ELSA-2022-8057

ELSA-2022-8057: grafana security, bug fix, and enhancement update (IMPORTANT)

около 3 лет назад
oracle-oval логотип
ELSA-2022-7519

ELSA-2022-7519: grafana security, bug fix, and enhancement update (MODERATE)

около 3 лет назад

Уязвимостей на страницу