Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-32276: Menus displayed even though user is not authenticated · Issue #50336 · grafana/grafana

** DISPUTED ** Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.

CVE
#vulnerability#web#auth

I’ve been trying to demonstrate that the vulnerability exists, but I believe you’re just focusing on the thought, "no data has been accessed", and at no time have I described it. The vulnerability lies in the following points:

If the user has installed plugins that add new features, these features will also be displayed in the menu. Even if the session does not return anything, the attacker will be able to see these features as they will be displayed in the side menus.
Another point is that with the use of a web proxy (Burp, OWASP ZAP, etc.) an attacker can access these menus and perform a reconnaissance of the endpoints, even if it does not return data because it is not a valid session, the attacker will have a view how calls are made and which endpoints.

This flaw could be categorized as A04:2021 Insecure_Design

Understand I’m trying to contribute to the security of the system.

Related news

CVE-2022-32275: grafana/README.md at main · BrotherOfJhonny/grafana

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907