CVE-2018-15727 PUBLISHED

Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.

EPSS 79.55% · 99.1th percentile

Risk Scores

EPSS Score
79.55%
99.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSgrafana0, 2.6.0+dfsg-1

Timeline

References

Open in Interactive Console →