Bug 2066563 (CVE-2022-26148) - CVE-2022-26148 grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix
Summary: CVE-2022-26148 grafana: An information leak issue was discovered in Grafana t...
Keywords:
Status: NEW
Alias: CVE-2022-26148
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2068519 2068520 2072831 2072832 2072833 2077636 2077637 2077638 2077639
Blocks: 2066564
TreeView+ depends on / blocked
 
Reported: 2022-03-22 04:50 UTC by Rohit Keshri
Modified: 2025-08-08 12:49 UTC (History)
55 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:3642 0 None None None 2023-06-15 15:59:48 UTC

Description Rohit Keshri 2022-03-22 04:50:47 UTC
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

https://2k8.org/post-319.html

Comment 27 errata-xmlrpc 2023-06-15 15:59:44 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 6.1

Via RHSA-2023:3642 https://access.redhat.com/errata/RHSA-2023:3642


Note You need to log in before you can comment on or make changes to this bug.