PT-2022-7304 · Grafana+3 · Grafana Enterprise+4

Xlson

·

Published

2022-05-20

·

Updated

2025-09-29

·

CVE-2022-29170

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions Grafana Enterprise versions 7.4.0-beta1 through 7.5.15 Grafana Enterprise versions 8.0.0 through 8.5.2
Description The issue is related to the Request security feature in Grafana Enterprise, which allows configuring the instance to only call specific hosts. However, a malicious datasource running on an allowed host can bypass these security configurations by returning an HTTP redirect to a forbidden host. This can potentially give secure information to clients. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a possibility to add a custom datasource that returns HTTP redirects.
Recommendations For Grafana Enterprise versions 7.4.0-beta1 through 7.5.15, update to version 7.5.16 or later. For Grafana Enterprise versions 8.0.0 through 8.5.2, update to version 8.5.3 or later. As a temporary workaround, consider restricting the addition of custom datasources to minimize the risk of exploitation. Avoid using the Request security allow list feature until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2022-3295
ALT-PU-2023-1161
ALT-PU-2023-4133
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2024-02598
BIT-GRAFANA-2022-29170
CVE-2022-29170
GHSA-9RRR-6FQ2-4F99
OESA-2022-1711
OPENSUSE-SU-2022_4428-1
OPENSUSE-SU-2022_4437-1
OPENSUSE-SU-2024:12282-1
SUSE-SU-2022:4428-1
SUSE-SU-2022:4437-1
SUSE-SU-2022:4439-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Grafana
Grafana Enterprise
Red Os
Suse