PT-2022-19149 · Grafana · Grafana Enterprise Logs+1

Published

2022-05-20

·

Updated

2024-03-06

·

CVE-2022-28660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana Enterprise Logs versions 1.1.x through 1.3.x
Description The querier component does not require authentication when X-Scope-OrgID is used, affecting -auth.type=enterprise in microservices mode.
Recommendations For versions 1.1.x through 1.3.x, update to version 1.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the querier component until a patch is available. Avoid using the X-Scope-OrgID header in the affected microservices mode until the issue is resolved.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-2022-28660
CVE-2022-28660

Affected Products

Grafana
Grafana Enterprise Logs