Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1624088 - (CVE-2018-15727) CVE-2018-15727 grafana: authentication bypass knowing only a username of an LDAP or OAuth user
CVE-2018-15727 grafana: authentication bypass knowing only a username of an ...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180829,repor...
: Security
Depends On: 1626399 1626400 1626401 1626866 1626867
Blocks: 1624089
  Show dependency treegraph
 
Reported: 2018-08-30 18:11 EDT by Laura Pardo
Modified: 2018-09-23 23:17 EDT (History)
18 users (show)

See Also:
Fixed In Version: grafana 5.2.3, grafana 4.6.4
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Laura Pardo 2018-08-30 18:11:09 EDT
A flaw was found in Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.


References:
https://grafana.com/blog/2018/08/29/grafana-5.2.3-and-4.6.4-released-with-important-security-fix/
Comment 1 Siddharth Sharma 2018-08-31 07:11:04 EDT
Reading code following seem to be fixes for this

For 5.2.x: https://github.com/grafana/grafana/commit/df83bf10a225811927644bdf6265fa80bdea9137
For 4.6.x: https://github.com/grafana/grafana/commit/7baecf0d0deae0d865e45cf03e082bc0db3f28c3
Comment 4 Siddharth Sharma 2018-09-07 02:22:37 EDT
Mitigation:

As per upstream (https://grafana.com/blog/2018/08/29/grafana-5.2.3-and-4.6.4-released-with-important-security-fix)

* Switch to authentication mechanism other than LDAP or OAuth
* Grafana should be isolated from public networks

Note You need to log in before you can comment on or make changes to this bug.