QID 150650

Date Published: 2023-02-22

QID 150650: Grafana Sensitive Information Disclosure Vulnerability (CVE-2022-23498)

Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.

When datasource query caching is enabled, Grafana caches all headers, including "grafana_session". As a result, any user that queries a datasource where the caching is enabled can acquire another users session.

Affected Versions:
Grafana versions from 8.3.1 to 9.2.7
Grafana versions from 9.3.0 to 9.3.2

QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a Grafana running on the target application.

Successful exploitation of this vulnerability could allow an unauthorized attacker to gain Sensitive Information.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Grafana to later version to remediate this vulnerability. For more information regarding this vulnerability please refer Github Advisory.

    CVEs related to QID 150650

    Software Advisories
    Advisory ID Software Component Link
    Github URL Logo github.com/grafana/grafana/security/advisories/GHSA-2j8f-6whh-frc8