CVE-2022-39324
Summary
| CVE | CVE-2022-39324 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-27 23:15:00 UTC |
| Updated | 2023-02-07 20:17:00 UTC |
| Description | Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The `Open original dashboard` button no longer points to the to the real original dashboard but to the attacker’s injected URL. This issue is fixed in versions 8.5.16 and 9.2.8. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Spoofing originalUrl of snapshots · Advisory · grafana/grafana · GitHub | MISC | github.com | |
| [v9.2.x] Snapshots: Build snapshot originalUrl on the backend (#6023… · grafana/grafana@d7dcea7 · GitHub | MISC | github.com | |
| Snapshots: Build snapshot originalUrl on the backend (#60232) · grafana/grafana@239888f · GitHub | MISC | github.com | |
| Snapshots: Build snapshot originalUrl on the backend by dprokop · Pull Request #60232 · grafana/grafana · GitHub | MISC | github.com | |
| [v9.2.x] Snapshots: Build snapshot originalUrl on the backend (#60232) by axelavargas · Pull Request #60256 · grafana/grafana · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150645 Grafana Spoofing originalUrl of snapshots Vulnerability (CVE-2022-39324)
- 161102 Oracle Enterprise Linux Security Update for grafana security and enhancement update (ELSA-2023-6420)
- 242309 Red Hat Update for grafana (RHSA-2023:6420)
- 691054 Free Berkeley Software Distribution (FreeBSD) Security Update for grafana (e6281d88-a7a7-11ed-8d6a-6c3be5272acd)
- 753815 SUSE Enterprise Linux Security Update for SUSE Manager Client Tools (SUSE-SU-2023:0812-1)
- 941404 AlmaLinux Security Update for grafana (ALSA-2023:6420)