VulnerabilityModified
CVE-2018-15727
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
CRITICAL 9.8EPSS 64.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 64.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 64.28% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- grafana/grafana · redhat/ceph storage
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/105184Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3829Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0019Third Party Advisory
- https://grafana.com/blog/2018/08/29/grafana-5.2.3-and-4.6.4-released-with-important-security-fix/Patch, Vendor Advisory
- http://www.securityfocus.com/bid/105184Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3829Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0019Third Party Advisory
- https://grafana.com/blog/2018/08/29/grafana-5.2.3-and-4.6.4-released-with-important-security-fix/Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.