Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2181
HistoryJul 04, 2023 - 1:37 p.m.

Advisory ROSA-SA-2023-2181

2023-07-0413:37:03
ROSA LAB
abf.rosalinux.ru
7
grafana 6.7.4
rosa virtualization 2.1
authentication bypass
remote attack
user account access
configuration file
azure ad

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

51.3%

Software: Grafana 6.7.4
OS: ROSA Virtualization 2.1

package_evr_string: grafana-6.7.4-3.rv3.src.rpm

CVE-ID: CVE-2023-3128
BDU-ID: 2023-03343
CVE-Crit: CRITICAL.
CVE-DESC.: A vulnerability in the Grafana web-based data submission tool is related to authentication bypass via spoofing. Exploitation of the vulnerability could allow an attacker acting remotely to gain full access to a user account
CVE-STATUS: Not Applicable
CVE-REV: You must disable Azure AD access in the configuration file located at /etc/grafana/grafana.ini.

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchgrafana< 6.7.4UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

51.3%