Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/grafana/synthetic-monitoring-agent
  4. ›
  5. CVE-2022-46156

CVE-2022-46156: Default installation of `synthetic-monitoring-agent` exposes sensitive information

September 6, 2024 (updated November 18, 2024)

Users running the Synthetic Monitoring agent in their local network are impacted. The authentication token used to communicate with the Synthetic Monitoring API is exposed thru a debugging endpoint. This token can be used to retrieve the Synthetic Monitoring checks created by the user and assigned to the agent identified with that token. The Synthetic Monitoring API will reject connections from already-connected agents, so access to the token does not guarantee access to the checks.

References

  • github.com/advisories/GHSA-9j4f-f249-q5w8
  • github.com/grafana/synthetic-monitoring-agent
  • github.com/grafana/synthetic-monitoring-agent/commit/d8dc7f9c1c641881cbcf0a09e178b90ebf0f0228
  • github.com/grafana/synthetic-monitoring-agent/pull/373
  • github.com/grafana/synthetic-monitoring-agent/pull/374
  • github.com/grafana/synthetic-monitoring-agent/pull/375
  • github.com/grafana/synthetic-monitoring-agent/releases/tag/v0.12.0
  • github.com/grafana/synthetic-monitoring-agent/security/advisories/GHSA-9j4f-f249-q5w8
  • nvd.nist.gov/vuln/detail/CVE-2022-46156
  • pkg.go.dev/vuln/GO-2022-1132

Code Behaviors & Features

Detect and mitigate CVE-2022-46156 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.12.0

Fixed versions

  • 0.12.0

Solution

Upgrade to version 0.12.0 or above.

Impact 3.3 LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-489: Active Debug Code
  • CWE-749: Exposed Dangerous Method or Function

Source file

go/github.com/grafana/synthetic-monitoring-agent/CVE-2022-46156.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:52 +0000.