CVE-2022-39201
Summary
| CVE | CVE-2022-39201 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-13 23:15:00 UTC |
| Updated | 2022-10-19 14:08:00 UTC |
| Description | Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Grafana | Grafana | All | All | All | All |
| Application | Grafana | Grafana | 5.0.0 | - | All | All |
| Application | Grafana | Grafana | 5.0.0 | beta1 | All | All |
| Application | Grafana | Grafana | 5.0.0 | beta2 | All | All |
| Application | Grafana | Grafana | 5.0.0 | beta3 | All | All |
| Application | Grafana | Grafana | 5.0.0 | beta4 | All | All |
| Application | Grafana | Grafana | 5.0.0 | beta5 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security: Fix do not forward login cookie in outgoing requests · grafana/grafana@b571acc · GitHub | MISC | github.com | |
| Release 9.1.8 (2022-10-11) · grafana/grafana · GitHub | MISC | github.com | |
| Security: Fix do not forward login cookie in outgoing requests · grafana/grafana@c658816 · GitHub | MISC | github.com | |
| Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins · Advisory · grafana/grafana · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161102 Oracle Enterprise Linux Security Update for grafana security and enhancement update (ELSA-2023-6420)
- 242309 Red Hat Update for grafana (RHSA-2023:6420)
- 690990 Free Berkeley Software Distribution (FreeBSD) Security Update for grafana (6877e164-6296-11ed-9ca2-6c3be5272acd)
- 753668 SUSE Enterprise Linux Security Update for grafana (SUSE-SU-2023:0362-1)
- 941404 AlmaLinux Security Update for grafana (ALSA-2023:6420)