Bug 1197515 (CVE-2022-26148) - VUL-0: CVE-2022-26148: grafana: information leak when integrated with Zabbix
Summary: VUL-0: CVE-2022-26148: grafana: information leak when integrated with Zabbix
Status: RESOLVED INVALID
Alias: CVE-2022-26148
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Witek Bedyk
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/326889/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-03-25 09:52 UTC by Thomas Leroy
Modified: 2022-07-26 08:03 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-03-25 09:52:55 UTC
rh#2066563

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

https://2k8.org/post-319.html

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2066563
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-26148
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26148
https://2k8.org/post-319.html
Comment 1 Thomas Leroy 2022-03-25 09:56:20 UTC
I can't see any upstream acknowledgment
Comment 2 Fergal Mc Carthy 2022-03-30 15:41:08 UTC
SOC 8/9 CLM don't deploy Grafana, so won't be affected.

SOC 8/9 Crowbar do deploy Grafana, but don't deploy Zabbix, so shouldn't be affected.
Comment 3 Christian Almeida de Oliveira 2022-03-30 15:56:05 UTC
based on comment #2, back to Security team.
Comment 4 Gianluca Gabrielli 2022-03-31 10:52:37 UTC
Witold are you maintaining the following packages? If so, could you submit the patch?
- SUSE:SLE-12:Update/grafana
- SUSE:SLE-15:Update/grafana
Comment 5 Gabriele Sonnu 2022-07-26 08:03:07 UTC
We either ship a newer version of Grafana (8.3.5) or don't ship Zabbix in our products, so we're not affected. Closing.