公告ID: KYLIN-2020-13379
安全等级: 中等
产品: Kylin V3
发布日期: 2020年6月3日
CVE: CVE-2020-13379
CVSS3评分: 7.5
概述:
In both OpenShift Container Platform (OCP) and OpenShift ServiceMesh (OSSM), the grafana containers are behind OpenShift OAuth restricting access to the vulnerable path to authenticated users only. Therefore, for both (OCP and OSSM) the impact is low. 描述:
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. 系统版本:
KYLIN 3.4.x
受影响包列表:
grafana