PT-2022-7314 · Grafana+1 · Grafana+1

Published

2022-11-08

·

Updated

2024-06-05

·

CVE-2022-39328

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana versions 9.2.0 through 9.2.3
Description Grafana is an open-source platform for monitoring and observability. The issue is related to a race condition in the authentication middlewares logic, which may allow an unauthenticated user to query an administration endpoint under heavy load. This could potentially allow a remote attacker to elevate their privileges. There are no known workarounds for this issue.
Recommendations For versions 9.2.0 through 9.2.3, update to version 9.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to administration endpoints to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02627
BIT-GRAFANA-2022-39328
CVE-2022-39328
GHSA-VQC4-MPJ8-JXCH
GO-2024-2856
RHSA-2023:6420

Affected Products

Grafana
Red Os