PT-2023-8913 · Grafana+3 · Grafana+3

Joaxcar

·

Published

2023-04-26

·

Updated

2024-06-15

·

CVE-2023-1387

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions 9.1 and later
Description The issue is related to the ability to search for a JWT in the URL query parameter auth token and use it as the authentication token. By enabling the "url login" configuration option, a JWT might be sent to data sources. If an attacker has access to the data source, the leaked token could be used to authenticate to Grafana. This could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For Grafana versions 9.1 and later, consider disabling the "url login" configuration option to prevent JWT tokens from being sent to data sources. As a temporary workaround, restrict access to data sources to minimize the risk of exploitation. Avoid using the auth token parameter in URL queries until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4133
ALT-PU-2023-4148
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2024-02593
BIT-GRAFANA-2023-1387
CVE-2023-1387
GHSA-5585-M9R5-P86J
OPENSUSE-SU-2024:12890-1
SUSE-SU-2023:2575-1
SUSE-SU-2023:2578-1
SUSE-SU-2023:2579-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Grafana
Red Os
Suse