PT-2022-16892 · Grafana+1 · Grafana Enterprise+2
Published
2022-04-12
·
Updated
2025-09-29
·
CVE-2022-24812
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grafana Enterprise versions prior to 8.1.0-beta1
Description
The issue arises when fine-grained access control is enabled and multiple API Keys with different roles are used within the same organization. Due to the caching mechanism, permissions for an API Key are cached for 30 seconds, leading to potential privilege escalation. For instance, if a request is made with an Admin API Key, subsequent requests with a Viewer API Key may inherit the cached Admin permissions, allowing access to higher privileges than intended.
Recommendations
For versions prior to 8.1.0-beta1, upgrade to a version after 8.1.0-beta1 as soon as possible.
As a temporary workaround, consider disabling fine-grained access control to mitigate the issue.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Grafana
Grafana Enterprise