CVE-2022-31130

Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*

History

17 Oct 2022, 13:31

Type Values Removed Values Added
First Time Grafana
Grafana grafana
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-200 CWE-522
CPE cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
References (MISC) https://github.com/grafana/grafana/commit/4dd56e4dabce10007bf4ba1059bf54178c35b177 - (MISC) https://github.com/grafana/grafana/commit/4dd56e4dabce10007bf4ba1059bf54178c35b177 - Patch, Third Party Advisory
References (MISC) https://github.com/grafana/grafana/commit/9da278c044ba605eb5a1886c48df9a2cb0d3885f - (MISC) https://github.com/grafana/grafana/commit/9da278c044ba605eb5a1886c48df9a2cb0d3885f - Patch, Third Party Advisory
References (CONFIRM) https://github.com/grafana/grafana/security/advisories/GHSA-jv32-5578-pxjc - (CONFIRM) https://github.com/grafana/grafana/security/advisories/GHSA-jv32-5578-pxjc - Patch, Third Party Advisory
References (MISC) https://github.com/grafana/grafana/releases/tag/v9.1.8 - (MISC) https://github.com/grafana/grafana/releases/tag/v9.1.8 - Release Notes, Third Party Advisory

13 Oct 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-13 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-31130

Mitre link : CVE-2022-31130

CVE.ORG link : CVE-2022-31130


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-522

Insufficiently Protected Credentials

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor