PT-2022-7310 · Grafana+5 · Grafana+5

Marefrauthored

+1

·

Published

2022-10-13

·

Updated

2025-09-29

·

CVE-2022-31130

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 9.1.8 Grafana versions prior to 8.5.14
Description The issue is related to the transmission of authentication tokens to certain destination plugins in the Grafana platform, which could allow a remote attacker to disclose protected information. This affects data source and plugin proxy endpoints with authentication tokens, potentially allowing the destination plugin to receive a user's Grafana authentication token.
Recommendations For versions prior to 9.1.8, update to version 9.1.8 or later to resolve the issue. For versions prior to 8.5.14, update to version 8.5.14 or later to resolve the issue. As a temporary workaround, consider avoiding the use of API keys, JWT authentication, or any HTTP Header based authentication until the issue is resolved.

Exploit

Fix

Information Disclosure

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6420
ALSA-2025_16880
ALT-PU-2022-3295
ALT-PU-2023-1161
ALT-PU-2023-4567
BDU:2024-02620
BIT-GRAFANA-2022-31130
CVE-2022-31130
GHSA-JV32-5578-PXJC
GO-2024-2851
OESA-2025-1186
OESA-2025-1187
OESA-2025-1188
OESA-2025-1189
OPENSUSE-SU-2023_0353-1
OPENSUSE-SU-2023_0362-1
OPENSUSE-SU-2024:12508-1
RHSA-2023:6420
RHSA-2023_6420
SUSE-SU-2023:0352-1
SUSE-SU-2023:0353-1
SUSE-SU-2023:0362-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Almalinux
Grafana
Red Hat
Red Os
Suse