CVE-2022-31130
Last modified
CVE-2022-31130 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Grafana | Grafana | < 8.5.14 |
| Grafana | Grafana | >= 9.0.0, < 9.1.8 |
References
- https://github.com/grafana/grafana/commit/4dd56e4dabce10007bf4ba1059bf54178c35b177Patch, Third Party Advisory
- https://github.com/grafana/grafana/commit/9da278c044ba605eb5a1886c48df9a2cb0d3885fPatch, Third Party Advisory
- https://github.com/grafana/grafana/releases/tag/v9.1.8Release Notes, Third Party Advisory
- https://github.com/grafana/grafana/security/advisories/GHSA-jv32-5578-pxjcPatch, Third Party Advisory
- https://github.com/grafana/grafana/commit/4dd56e4dabce10007bf4ba1059bf54178c35b177Patch, Third Party Advisory
- https://github.com/grafana/grafana/commit/9da278c044ba605eb5a1886c48df9a2cb0d3885fPatch, Third Party Advisory
- https://github.com/grafana/grafana/releases/tag/v9.1.8Release Notes, Third Party Advisory
- https://github.com/grafana/grafana/security/advisories/GHSA-jv32-5578-pxjcPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31130?
How severe is CVE-2022-31130?
How do I fix CVE-2022-31130?
Are you affected by CVE-2022-31130?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
