CVE-2023-1387
Discription

Grafana is an open-source platform for monitoring and observability.
Starting with the 9.1 branch, Grafana introduced the ability to search for
a JWT in the URL query parameter auth_token and use it as the
authentication token. By enabling the “url_login” configuration option
(disabled by default), a JWT might be sent to data sources. If an attacker
has access to the data source, the leaked token could be used to
authenticate to Grafana.Read More

Back to Main

Subscribe for the latest news: