Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-08-29T15:00:00

Updated: 2024-08-05T10:01:54.541Z

Reserved: 2018-08-22T00:00:00

Link: CVE-2018-15727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-08-29T15:29:00.240

Modified: 2019-03-05T17:26:49.527

Link: CVE-2018-15727

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-08-29T00:00:00Z

Links: CVE-2018-15727 - Bugzilla