CVE-2022-26148: Critical severity grafana labs grafana oss and enterprise vulnerability
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the apijsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in apijsonrpc.php to discover the Zabbix account password and URL address.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26148?
CVE-2022-26148 is a vulnerability in Grafana through 7.3.4 when integrated with Zabbix, which allows an attacker to find the Zabbix password in the HTML source code.
What is the severity of CVE-2022-26148?
The severity of CVE-2022-26148 is critical, with a severity score of 9.8.
How does CVE-2022-26148 affect Grafana?
CVE-2022-26148 affects Grafana versions up to 7.3.4 when integrated with Zabbix, exposing the Zabbix password in the api_jsonrpc.php HTML source code.
How can I fix CVE-2022-26148?
To fix CVE-2022-26148, it is recommended to update Grafana to a version beyond 7.3.4.
Is there any additional information available about CVE-2022-26148?
Yes, you can find additional information about CVE-2022-26148 in the provided references: [Reference 1](https://2k8.org/post-319.html), [Reference 2](https://access.redhat.com/errata/RHSA-2023:3642), [Reference 3](https://bugzilla.redhat.com/show_bug.cgi?id=2066563).