CVE-2022-31130

Name
CVE-2022-31130
Description
Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/grafana/grafana/security/advisories/GHSA-jv32-5578-pxjc
MISC https://github.com/grafana/grafana/releases/tag/v9.1.8
MISC https://github.com/grafana/grafana/commit/4dd56e4dabce10007bf4ba1059bf54178c35b177
MISC https://github.com/grafana/grafana/commit/9da278c044ba605eb5a1886c48df9a2cb0d3885f

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* grafana >= 9.0.0 < 9.1.8
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* grafana >= None < 8.5.14

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
grafana 3.16-community 8.5.13-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable