Bug 2186322 (CVE-2023-1387)

Summary: CVE-2023-1387 grafana: JWT token leak to data source
Product: [Other] Security Response Reporter: Pedro Sampaio <psampaio>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amctagga, aoconnor, bniver, dfreiber, flucifre, gmeno, gparvin, grafana-maint, jburrell, jkurik, jwendell, mbenjamin, mhackett, nathans, njean, owatkins, pahickey, rcernich, rogbas, sostapov, stcannon, teagle, twalsh, vereddy, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: grafana 9.5.0 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Grafana. This flaw allows a remote, authenticated attacker to obtain sensitive information caused by an issue when enabling the "url_login" configuration option. By sending a specially crafted request, an attacker can obtain JWT information and use this to launch further attacks against the affected system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2187245, 2187246, 2187247, 2187592, 2187593, 2203041, 2254041    
Bug Blocks: 2186323    

Description Pedro Sampaio 2023-04-12 21:06:46 UTC
Where an attacker has control on a datasource, the JWT token can be leaked to the data source when the GF_AUTH_JWT_URL_TOKEN is set to true.

References:

https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/jwt/?mkt_tok=MzU2LVlGRy0zODkAAAGLFetKhj7bubnwJdat7dsOUsknnKYqQ9qYPFzMoSlKt-Q2six9bJNYh9F9jYhkMcc7sxu_Zgchs7ypuWq1wvGij0ouoSHS40eCT0UURdmmvRo#url-login

Comment 4 Avinash Hanwate 2023-05-11 06:15:44 UTC
Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2203041]

Comment 6 errata-xmlrpc 2023-12-12 13:56:31 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 6.1

Via RHSA-2023:7741 https://access.redhat.com/errata/RHSA-2023:7741

Comment 7 errata-xmlrpc 2024-02-08 16:58:19 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 5.3

Via RHSA-2024:0746 https://access.redhat.com/errata/RHSA-2024:0746