The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode
References
Link | Resource |
---|---|
https://grafana.com/docs/enterprise-logs/latest/gel-releases/#v121----may-3-2022 | Release Notes Vendor Advisory |
https://security.netapp.com/advisory/ntap-20220707-0004/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-05-20 08:15
Updated : 2022-10-07 08:45
NVD link : CVE-2022-28660
Mitre link : CVE-2022-28660
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
grafana
- grafana