SB2024050722 - SUSE update for grafana and mybatis
Published: May 7, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Incorrect authorization (CVE-ID: CVE-2023-6152)
The vulnerability allows a remote attacker to bypass email verification.
The vulnerability exists due to email addresses are verified only during sign up, if "verify_email_enabled" option is set. A remote attacker can register an account and then set an arbitrary email address without verification.
2) Improper Authorization (CVE-ID: CVE-2024-1313)
The vulnerability allows a remote attacker to bypass authorization.
The vulnerability exists due to improper authorization checks. A remote user outside an organization can send a DELETE request to /api/snapshots/ using its view key to bypass authorization and delete a snapshot.
Remediation
Install update from vendor's website.