Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability
References
Link Resource
https://github.com/BrotherOfJhonny/grafana/blob/main/README.md Exploit Third Party Advisory
https://github.com/grafana/grafana/issues/50336 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-17T11:38:27

Updated: 2022-06-17T11:38:27

Reserved: 2022-06-03T00:00:00


Link: CVE-2022-32276

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-06-17T13:15:16.443

Modified: 2024-05-17T02:09:54.600


Link: CVE-2022-32276

JSON object: View

cve-icon Redhat Information

No data.

CWE