Bug 2102254 (CVE-2022-32275) - CVE-2022-32275 grafana: session control failure may lead to information disclosure
Summary: CVE-2022-32275 grafana: session control failure may lead to information discl...
Keywords:
Status: NEW
Alias: CVE-2022-32275
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2102623 2102625 2102626
Blocks: 2102255
TreeView+ depends on / blocked
 
Reported: 2022-06-29 14:18 UTC by Marian Rehak
Modified: 2023-07-07 08:32 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in grafana. This vulnerability occurs when the traversal path is explored, and the authentication system redirects to an internal system page that authenticated users should only access.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marian Rehak 2022-06-29 14:18:37 UTC
Grafana allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

Reference:

https://github.com/grafana/grafana/issues/50336

Comment 1 Andreas Gerstmayr 2022-06-29 14:55:09 UTC
Hi Marian,

can you please add a reproducer, for example using curl, and note which Grafana version(s) are affected?
I cannot reproduce it so far using the above path on Grafana 7 or 8.


Thanks,
Andreas

Comment 7 Sandipan Roy 2022-06-30 11:42:30 UTC
Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2102623]


Note You need to log in before you can comment on or make changes to this bug.