PT-2022-20588 · Grafana · Grafana

Published

2022-09-02

·

Updated

2024-03-06

·

CVE-2022-31176

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 3.6.1
Description An unauthorized file disclosure issue was identified in Grafana, allowing a malicious user to retrieve unauthorized files under certain network conditions or via a fake datasource, particularly if the user has admin permissions.
Recommendations For versions prior to 3.6.1, upgrade to version 3.6.1 as soon as possible. As a temporary workaround, consider disabling HTTP remote rendering.

Exploit

Fix

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-IMAGE-RENDERER-2022-31176
CVE-2022-31176
GHSA-2CFH-233G-M4C5

Affected Products

Grafana