Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40376
HistoryMay 02, 2023 - 4:31 a.m.

Information Disclosure

2023-05-0204:31:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
43
information disclosure
jwt
auth_jwt.go
proxy requests
data sources

0.001 Low

EPSS

Percentile

46.5%

github.com/grafana/grafana is vulnerable to Information Disclosure. The vulnerability exists in the initContextWithJWT function of auth_jwt.go because the JWT URL-login flow leaks tokens to data sources through request parameters in proxy requests.