Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37585
HistoryOct 17, 2022 - 11:15 a.m.

Information Disclosure

2022-10-1711:15:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
grafana
information disclosure
vulnerability
proxy endpoints
sensitive authentication tokens
http header information.

0.001 Low

EPSS

Percentile

44.1%

grafana is vulnerable to information disclosure. The vulnerability is due to the proxy endpoints leaking sensitive authentication tokens to some destination plugins which allows an attacker to gain access to HTTP header information.