Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33791
HistoryJan 20, 2022 - 8:41 a.m.

Information Disclosure

2022-01-2008:41:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
github
grafana
information disclosure
oauth
identity
data source
attacker
sensitive data
vulnerability

EPSS

0.001

Percentile

44.4%

github.com/grafana/grafana is vulnerable to information disclosure. When the forward auth identity is enabled, the library sends the OAuth identity of the most recently logged-in user when sending a query to the data source, allowing an attacker to retrieve sensitive data from the most recently logged-in user.