Lucene search

K
redhatcveRedhat.comRH:CVE-2022-23498
HistoryFeb 06, 2023 - 5:26 a.m.

CVE-2022-23498

2023-02-0605:26:03
redhat.com
access.redhat.com
35
grafana package
data source query caching
vulnerability
session acquisition
mitigation

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

36.5%

A flaw was found in the Grafana package. When data-source query caching is enabled, Grafana caches all headers, including grafana_session. As a result, any user that queries a data source where the caching is enabled can acquire another user’s session.

Mitigation

To mitigate the vulnerability, disable the data source query caching for all data sources.

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

36.5%