Grafana Authentication Bypass
Critical severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
< 4.6.4
>= 5.0.0, < 5.2.3
Patched versions
4.6.4
5.2.3
Description
Reviewed
May 20, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Oct 2, 2023
Grafana before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
Specific Go Packages Affected
github.com/grafana/grafana/pkg/api
References