Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://github.com/grafana/grafana/security/advisories/GHSA-3p62-42x7-gxg5 | vendor advisory |
https://security.netapp.com/advisory/ntap-20221215-0004/ | third party advisory |