VDB
CVE-2022-39307
CVE-2022-39307
PUBLISHED
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.
EPSS 0.22% · 44.6th percentile
Risk Scores
EPSS Score
0.22%
44.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 0, 9.0.0 |
| Bitnami | grafana | 0, 9.0.0 |
Timeline
- Nov 8, 2022 CVE Published
- Nov 9, 2022 CVE Updated
- Nov 10, 2022 EPSS Score
- Dec 23, 2022 EPSS Score
- Feb 4, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 19, 2023 EPSS Score
- Jun 13, 2023 EPSS Score
- Jul 26, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
- Oct 20, 2023 EPSS Score
- Dec 2, 2023 EPSS Score