Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37584
HistoryOct 17, 2022 - 8:35 a.m.

Authentication Bypass

2022-10-1708:35:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
authentication bypass
grafana
getuserbylogin
user.go
unauthorized access
vulnerability

0.001 Low

EPSS

Percentile

48.5%

grafana is vulnerable to Authentication Bypass. The vulnerability exists due to the GetUserByLogin function in user.go conflict in the login field; An attacker can register into the system from another user’s email address as a username blocking a user’s login attempt.