PT-2022-7302 · Grafana+7 · Grafana+7

Kminehart

+1

·

Published

2022-01-18

·

Updated

2025-09-29

·

CVE-2022-21673

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 7.5.13 Grafana versions prior to 8.3.4
Description The issue is related to the Forward OAuth Identity feature in Grafana, which can allow API token holders to retrieve data for which they may not have intended access. This occurs when a data source has the Forward OAuth Identity feature enabled and a query is sent to that data source with an API token and no other user credentials, forwarding the OAuth Identity of the most recently logged-in user. The attack relies on specific conditions, including the presence of data sources that support the Forward OAuth Identity feature, the feature being toggled on for a data source, OAuth being enabled, and the presence of usable API keys.
Recommendations For versions prior to 7.5.13, update to version 7.5.13 or later. For versions prior to 8.3.4, update to version 8.3.4 or later. As a temporary workaround, consider disabling the Forward OAuth Identity feature for all data sources until a patch is applied. Restrict access to data sources that support the Forward OAuth Identity feature to minimize the risk of exploitation. Avoid using API tokens for queries to data sources with the Forward OAuth Identity feature enabled until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7519
ALSA-2022:8057
ALSA-2025_16880
ALT-PU-2022-1806
ALT-PU-2022-1820
ALT-PU-2023-4567
BDU:2024-02596
BIT-GRAFANA-2022-21673
CESA-2022_7519
CVE-2022-21673
GHSA-8WJH-59CW-9XH4
OESA-2022-1531
OPENSUSE-SU-2022_1396-1
OPENSUSE-SU-2024:11816-1
RHSA-2022:7519
RHSA-2022:8057
RHSA-2022_7519
RHSA-2022_8057
RLSA-2022:7519
RLSA-2022:8057
SUSE-FU-2022:1419-1
SUSE-SU-2022:0751-1
SUSE-SU-2022:1396-1
SUSE-SU-2022:2134-1
SUSE-SU-2022:3676-1
SUSE-SU-2024:0191-1

Affected Products

Alt Linux
Almalinux
Centos
Grafana
Red Hat
Red Os
Rocky Linux
Suse