CVE-2022-39201

Name
CVE-2022-39201
Description
Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/grafana/grafana/security/advisories/GHSA-x744-mm8v-vpgr
MISC https://github.com/grafana/grafana/releases/tag/v9.1.8
MISC https://github.com/grafana/grafana/commit/c658816f5229d17f877579250c07799d3bbaebc9
MISC https://github.com/grafana/grafana/commit/b571acc1dc130a33f24742c1f93b93216da6cf57

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:grafana:grafana:5.0.0:beta1:*:*:*:*:*:* grafana == None == 5.0.0
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* grafana >= 9.0.0 < 9.1.8
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* grafana >= 5.0.1 < 8.5.14

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
grafana 3.16-community 8.5.13-r1 Konstantin Kulikov <k.kulikov2@gmail.com> possibly vulnerable