The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode
References
Link | Resource |
---|---|
https://grafana.com/docs/enterprise-logs/latest/gel-releases/#v121----may-3-2022 | Release Notes Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220707-0004/ | Third Party Advisory |
https://grafana.com/docs/enterprise-logs/latest/gel-releases/#v121----may-3-2022 | Release Notes Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220707-0004/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:57
Type | Values Removed | Values Added |
---|---|---|
References | () https://grafana.com/docs/enterprise-logs/latest/gel-releases/#v121----may-3-2022 - Release Notes, Vendor Advisory | |
References | () https://security.netapp.com/advisory/ntap-20220707-0004/ - Third Party Advisory |
Information
Published : 2022-05-20 15:15
Updated : 2024-11-21 06:57
NVD link : CVE-2022-28660
Mitre link : CVE-2022-28660
CVE.ORG link : CVE-2022-28660
JSON object : View
Products Affected
grafana
- grafana
CWE
CWE-306
Missing Authentication for Critical Function