QID 150650
Date Published: 2023-02-22
QID 150650: Grafana Sensitive Information Disclosure Vulnerability (CVE-2022-23498)
Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
When datasource query caching is enabled, Grafana caches all headers, including "grafana_session". As a result, any user that queries a datasource where the caching is enabled can acquire another users session.
Affected Versions:
Grafana versions from 8.3.1 to 9.2.7
Grafana versions from 9.3.0 to 9.3.2
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a Grafana running on the target application.
Successful exploitation of this vulnerability could allow an unauthorized attacker to gain Sensitive Information.
CVEs related to QID 150650
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Github |
|