Information disclosure in Grafana - CVE-2022-26148

 

Information disclosure in Grafana - CVE-2022-26148

Published: June 15, 2022 / Updated: June 16, 2022


Vulnerability identifier: #VU64388
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26148
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application when Grafana is integrated with Zabbix. A remote user can find Zabbix password in the api_jsonrpc.php HTML source code and gain unauthorized access to sensitive information on the system.


Affected software

Grafana
IBM Watson Machine Learning Accelerator
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Ceph Storage

How to mitigate CVE-2022-26148

Install updates from vendor's website.

Grafana - update to 7.3.5
IBM Watson Machine Learning Accelerator - update to 3.0.0
Red Hat Ceph Storage - update to 6.1

External References

Related Security Bulletins