Lucene search

K
osvGoogleOSV:CVE-2022-26148
HistoryMar 21, 2022 - 8:15 p.m.

CVE-2022-26148

2022-03-2120:15:14
Google
osv.dev
5

7.2 High

AI Score

Confidence

High

0.157 Low

EPSS

Percentile

96.0%

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

7.2 High

AI Score

Confidence

High

0.157 Low

EPSS

Percentile

96.0%