CVE-2022-31130
Summary
| CVE | CVE-2022-31130 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-13 23:15:00 UTC |
| Updated | 2022-10-17 13:31:00 UTC |
| Description | Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 9.1.8 (2022-10-11) · grafana/grafana · GitHub | MISC | github.com | |
| Security: Make proxy endpoints not leak sensitive HTTP headers · grafana/grafana@4dd56e4 · GitHub | MISC | github.com | |
| Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins · Advisory · grafana/grafana · GitHub | CONFIRM | github.com | |
| Plugins: Make proxy endpoints not leak sensitive HTTP headers · grafana/grafana@9da278c · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161102 Oracle Enterprise Linux Security Update for grafana security and enhancement update (ELSA-2023-6420)
- 242309 Red Hat Update for grafana (RHSA-2023:6420)
- 690988 Free Berkeley Software Distribution (FreeBSD) Security Update for grafana (6f6c9420-6297-11ed-9ca2-6c3be5272acd)
- 753668 SUSE Enterprise Linux Security Update for grafana (SUSE-SU-2023:0362-1)
- 941404 AlmaLinux Security Update for grafana (ALSA-2023:6420)