PT-2022-16892 · Grafana+1 · Grafana Enterprise+2

Published

2022-04-12

·

Updated

2025-09-29

·

CVE-2022-24812

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana Enterprise versions prior to 8.1.0-beta1
Description The issue arises when fine-grained access control is enabled and multiple API Keys with different roles are used within the same organization. Due to the caching mechanism, permissions for an API Key are cached for 30 seconds, leading to potential privilege escalation. For instance, if a request is made with an Admin API Key, subsequent requests with a Viewer API Key may inherit the cached Admin permissions, allowing access to higher privileges than intended.
Recommendations For versions prior to 8.1.0-beta1, upgrade to a version after 8.1.0-beta1 as soon as possible. As a temporary workaround, consider disabling fine-grained access control to mitigate the issue.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2022-1806
ALT-PU-2022-1820
ALT-PU-2023-4567
BIT-GRAFANA-2022-24812
CVE-2022-24812
GHSA-82GQ-XFG3-5J7V
OPENSUSE-SU-2024:12282-1

Affected Products

Alt Linux
Grafana
Grafana Enterprise