PT-2022-7309 · Grafana+5 · Grafana+5

Published

2022-10-13

·

Updated

2025-09-29

·

CVE-2022-39201

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Grafana versions 5.0.0-beta1 through 8.5.13 Grafana versions 9.0.0 through 9.1.7
Description The issue is related to the transmission of user authentication cookies to plugins, potentially allowing a remote attacker to disclose protected information. This affects data source and plugin proxy endpoints under certain conditions, where the destination plugin could receive a user's Grafana authentication cookie.
Recommendations For Grafana versions 5.0.0-beta1 through 8.5.13, update to version 8.5.14 to resolve the issue. For Grafana versions 9.0.0 through 9.1.7, update to version 9.1.8 to resolve the issue. As a temporary workaround, consider restricting access to data source and plugin proxy endpoints to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6420
ALSA-2025_16880
ALT-PU-2022-3295
ALT-PU-2023-1161
ALT-PU-2023-4567
BDU:2024-02619
BIT-GRAFANA-2022-39201
CVE-2022-39201
GHSA-X744-MM8V-VPGR
GO-2024-2858
OESA-2025-1186
OESA-2025-1187
OESA-2025-1188
OESA-2025-1189
OPENSUSE-SU-2023_0353-1
OPENSUSE-SU-2023_0362-1
OPENSUSE-SU-2024:12508-1
RHSA-2023:6420
RHSA-2023_6420
SUSE-SU-2023:0352-1
SUSE-SU-2023:0353-1
SUSE-SU-2023:0362-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Almalinux
Grafana
Red Hat
Red Os
Suse