CVE-2022-21673

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

History

14 May 2022, 03:16

Type Values Removed Values Added
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220303-0004/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220303-0004/ - Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/ - Mailing List, Third Party Advisory
References (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/ - (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/ - Mailing List, Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
First Time Fedoraproject
Fedoraproject fedora

07 May 2022, 08:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/ -

20 Apr 2022, 21:15

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/ -

03 Mar 2022, 11:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220303-0004/ -

26 Jan 2022, 14:30

Type Values Removed Values Added
First Time Grafana
Grafana grafana
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : 3.5
v3 : 4.3
CPE cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
References (MISC) https://github.com/grafana/grafana/releases/tag/v7.5.13 - (MISC) https://github.com/grafana/grafana/releases/tag/v7.5.13 - Release Notes, Third Party Advisory
References (CONFIRM) https://github.com/grafana/grafana/security/advisories/GHSA-8wjh-59cw-9xh4 - (CONFIRM) https://github.com/grafana/grafana/security/advisories/GHSA-8wjh-59cw-9xh4 - Third Party Advisory
References (MISC) https://github.com/grafana/grafana/releases/tag/v8.3.4 - (MISC) https://github.com/grafana/grafana/releases/tag/v8.3.4 - Release Notes, Third Party Advisory

18 Jan 2022, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-01-18 22:15

Updated : 2022-05-14 03:16


NVD link : CVE-2022-21673

Mitre link : CVE-2022-21673


JSON object : View

Products Affected

fedoraproject

  • fedora

grafana

  • grafana
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor