#VU64388 Information disclosure in Grafana - CVE-2022-26148
Published: June 15, 2022 / Updated: June 16, 2022
Grafana
Grafana Labs
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application when Grafana is integrated with Zabbix. A remote user can find Zabbix password in the api_jsonrpc.php HTML source code and gain unauthorized access to sensitive information on the system.