PT-2018-3433 · Grafana+1 · Grafana+1

Published

2018-08-29

·

Updated

2024-08-21

·

CVE-2018-15727

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Grafana versions 2.x through 4.x before 4.6.4 Grafana versions 5.x before 5.2.3
Description: The issue is related to authentication errors in the Grafana web tool, allowing an attacker to bypass authentication. This can be achieved by generating a valid "remember me" cookie with knowledge of only a username of an LDAP or OAuth user. The exploitation of this issue may impact the confidentiality, integrity, and availability of protected information.
Recommendations: For Grafana versions 2.x through 4.x before 4.6.4, update to version 4.6.4 or later. For Grafana versions 5.x before 5.2.3, update to version 5.2.3 or later. As a temporary workaround, consider restricting access to the github.com/grafana/grafana/pkg/api endpoint until a patch is available. Avoid using the remember me cookie feature in affected versions until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2486
BDU:2020-01361
CVE-2018-15727
ECHO-8B5E-2AAC-BACF
GHSA-RGJG-66CX-5X9M
GO-2022-0707
RHSA-2018:3829
RHSA-2019:0019
SUSE-SU-2019:2671-1
SUSE-SU-2019:2867-1
SUSE-SU-2020:1273-1

Affected Products

Alt Linux
Grafana