PT-2022-21200 · Grafana · Grafana

Thefrenchghosty

·

Published

2022-06-08

·

Updated

2026-05-26

·

CVE-2022-32276

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana version 8.4.3
Description The issue allows unauthenticated access via a "/dashboard/snapshot/*?orgId=0" URI. The vendor considers this a UI bug, not a vulnerability.
Recommendations For Grafana version 8.4.3, consider restricting access to the "/dashboard/snapshot/*" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the orgId parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-2022-32276
CVE-2022-32276

Affected Products

Grafana