Authentication mechanism absence or evasion In github.com/grafana/grafana
Description
Grafana Authentication Bypass Grafana before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
Specific Go Packages Affected
github.com/grafana/grafana/pkg/api
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 4.6.4, 5.2.3 | ||
go | 4.6.4, 5.2.3 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6.