PT-2022-7299 · Grafana+7 · Grafana+7

Kminehart

·

Published

2022-07-14

·

Updated

2025-09-29

·

CVE-2022-31107

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grafana versions 5.3 through 9.0.3 Grafana versions 8.3 through 8.3.10 Grafana versions 8.4 through 8.4.10 Grafana versions 8.5 through 8.5.9
Description The issue is related to an authorization problem in the Grafana platform, allowing a malicious user to take over another user's account. This can happen when the malicious user is authorized to log in via a configured OAuth IdP, their external user ID and email address are not associated with a Grafana account, and they know the target user's Grafana username. The malicious user can then set their username in the OAuth provider to that of the target user and log in to Grafana, gaining access to the target user's account.
Recommendations For versions 5.3 through 9.0.3, update to version 9.0.3 or later. For versions 8.3 through 8.3.10, update to version 8.3.10 or later. For versions 8.4 through 8.4.10, update to version 8.4.10 or later. For versions 8.5 through 8.5.9, update to version 8.5.9 or later. As a temporary workaround, consider disabling OAuth login to the Grafana instance, or ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5716
ALSA-2022:5717
ALSA-2025_16880
ALT-PU-2022-3295
ALT-PU-2023-1161
ALT-PU-2023-4133
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2024-02573
BIT-GRAFANA-2022-31107
CESA-2022_5717
CVE-2022-31107
GHSA-MX47-6497-3FV2
GO-2024-2852
OESA-2022-1870
OPENSUSE-SU-2022_3751-1
OPENSUSE-SU-2022_3765-1
OPENSUSE-SU-2022_4428-1
OPENSUSE-SU-2022_4437-1
OPENSUSE-SU-2024:12260-1
RHSA-2022:5716
RHSA-2022:5717
RHSA-2022:5718
RHSA-2022:5719
RHSA-2022:5720
RHSA-2022_5716
RHSA-2022_5717
RLSA-2022:5716
RLSA-2022:5717
SUSE-SU-2022:3676-1
SUSE-SU-2022:3747-1
SUSE-SU-2022:3751-1
SUSE-SU-2022:3765-1
SUSE-SU-2022:4428-1
SUSE-SU-2022:4437-1
SUSE-SU-2022:4439-1
SUSE-SU-2023:2575-1
SUSE-SU-2023:2578-1
SUSE-SU-2023:2579-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Almalinux
Centos
Grafana
Red Hat
Red Os
Rocky Linux
Suse