NA

CVE-2023-2183

Published: 06/06/2023 Updated: 06/07/2023
CVSS v3 Base Score: 6.4 | Impact Score: 2.7 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API does not check access to this function. This might enable malicious users to abuse the functionality by sending multiple alert messages to e-mail and Slack, spamming users, prepare Phishing attack or block SMTP server. Users may upgrade to version 9.5.3, 9.4.12, 9.3.15, 9.2.19 and 8.5.26 to receive a fix.

Vulnerable Product Search on Vulmon Subscribe to Product

grafana grafana

Vendor Advisories

Synopsis Important: Red Hat Ceph Storage 61 security, enhancements, and bug fix update Type/Severity Security Advisory: Important Topic Updated container image for Red Hat Ceph Storage 61 is now available in the Red Hat Ecosystem Catalog Description Red Hat Ceph Storage is a scalable, open, software-defined storage platform that combines ...
Synopsis Moderate: Red Hat Ceph Storage 61 security, enhancements, and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat Ceph Storage 61 in the Red Hat Ecosystem Catalo ...
Description<!---->A flaw was found in grafana This issue may allow a malicious user to craft a request to the API that enables them to send alert messages via the &amp;quot;API Alert - Test&amp;quot;A flaw was found in grafana This issue may allow a malicious user to craft a request to the API that enables them to send alert messages via the "AP ...