Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37705
HistoryOct 28, 2022 - 12:28 a.m.

Signature Verification Bypass

2022-10-2800:28:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
35
vulnerability
signature verification
grafana

EPSS

0.001

Percentile

32.7%

github.com/grafana/grafana is vulnerable to signature verification bypass. A local attacker is able to convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed, due to the improper verification of plugin signature.