github.com/grafana/grafana is vulnerable to information disclosure. When the forward auth identity is enabled, the library sends the OAuth identity of the most recently logged-in user when sending a query to the data source, allowing an attacker to retrieve sensitive data from the most recently logged-in user.
github.com/grafana/grafana/commit/2c0f961c59ea31d9086ab4fce64559e4b9603ac1
github.com/grafana/grafana/commit/bb0cfbc1d9ee75ba9c1068276e490e2868bb112f
github.com/grafana/grafana/pull/43204
github.com/grafana/grafana/releases/tag/v7.5.13
github.com/grafana/grafana/releases/tag/v8.3.4
github.com/grafana/grafana/security/advisories/GHSA-8wjh-59cw-9xh4
lists.fedoraproject.org/archives/list/[email protected]/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/
lists.fedoraproject.org/archives/list/[email protected]/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/
lists.fedoraproject.org/archives/list/[email protected]/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/
security.netapp.com/advisory/ntap-20220303-0004/