CVE-2022-26148
When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 53.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 53.44% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- grafana/grafana · redhat/ceph storage · redhat/storage
- Source
- cve@mitre.org
References
- https://2k8.org/post-319.htmlExploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220425-0005/Third Party Advisory
- https://2k8.org/post-319.htmlExploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220425-0005/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.