
=====================================================================

                                 CERT-Renater

                     Note d'Information No. 2023/VULN037

_____________________________________________________________________

DATE                : 31/01/2023

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Grafana Enterprise versions prior
                               to 9.3.2, 9.2.8, 8.5.16.

=====================================================================
https://github.com/grafana/grafana/security/advisories/GHSA-5hcf-rqj9-xh96
https://github.com/grafana/grafana/security/advisories/GHSA-8xmm-x63g-f6xv
_____________________________________________________________________


SAML privilege escalation
High
vtorosyan published GHSA-5hcf-rqj9-xh96 Jan 26, 2023

Package
SAML (Go)

Affected versions
6.3.0-beta1 - 9.3.1

Patched versions
9.3.2, 9.2.8, 8.5.16


Description

Summary

Grafana Enterprise is using crewjam/saml library for SAML integration.
On Nov 30, 2022 an advisory and relevant fix was published in the upstream
library, which described a vulnerability allowing privilege escalation
when processing SAML responses containing multiple assertions.

The vulnerability is possible to exploit only when a SAML document is not
signed and multiple assertions are being used, where at least one assertion
is signed. As a result, an attacker could intercept the SAML response and
add any unsigned assertion, which would be parsed as signed by the library.


Steps to reproduce

Log in with SAML with any credentials
Intercept the SAML response which contains one signed assertion
Add any new unsigned identity assertion containing Admin username/email
Forward the request to Grafana


Mitigations

To fully address CVE-2022-41912 please upgrade your Grafana instances. As
an alternative, you could ensure to sign the entire SAML document, or
stop using SAML temporarily.

Severity
High

8.3/ 10

CVSS base metrics

Attack vector
Network

Attack complexity
Low

Privileges required
Low

User interaction
None

Scope
Unchanged

Confidentiality
High

Integrity
High

Availability
Low

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CVE ID
CVE-2022-41912

Weaknesses
CWE-287

_____________________________________________________________________


Stored XSS in ResourcePicker component
High
vtorosyan published GHSA-8xmm-x63g-f6xv Jan 26, 2023

Package
github.com/grafana/grafana

Affected versions
 > =8.1

Patched versions
None


Description

Description

On 2022-12-16 during an internal audit of Grafana, a member of the
security team found a stored XSS vulnerability affecting the core
plugin GeoMap.

The stored XSS vulnerability was possible due to SVG-files weren't
properly sanitized and allowed arbitrary JavaScript to be executed
in the context of the currently authorized user of the Grafana
instance.


Impact

An attacker needs to have the Editor role in order to change a panel
to include either an external URL to a SVG-file containing JavaScript,
or use the data: scheme to load an inline SVG-file containing JavaScript.
This means that vertical privilege escalation is possible, where a
user with Editor role can change to a known password for a user having
Admin role if the user with Admin role executes malicious JavaScript
viewing a dashboard.


Impacted versions

All installations for Grafana versions >=8.1.x.


Solutions and mitigations

Update your Grafana instance.


Reporting security issues

If you think you have found a security vulnerability, please send a
report to security@grafana.com. This address can be used for all of
Grafana Labs' open source and commercial products (including, but not
limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com).
We can accept only vulnerability reports at this address. We would
prefer that you encrypt your message to us by using our PGP key.
The key fingerprint is

F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA

The key is available from keyserver.ubuntu.com.


Security announcements

We maintain a security category on our blog, where we will always
post a summary, remediation, and mitigation details for any patch
containing security fixes.

You can also subscribe to our RSS feed.


Severity
High

7.3/ 10

CVSS base metrics

Attack vector
Network

Attack complexity
Low

Privileges required
Low

User interaction
Required

Scope
Unchanged

Confidentiality
High

Integrity
High

Availability
None

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CVE ID
CVE-2022-23552

Weaknesses
CWE-79


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================


