CVE-2022-39201

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
Affected Products (NVD)
VendorProductVersion
grafanagrafana
5.0.1 ≤
𝑥
< 8.5.14
grafanagrafana
9.0.0 ≤
𝑥
< 9.1.8
grafanagrafana
5.0.0
grafanagrafana
5.0.0:beta1
grafanagrafana
5.0.0:beta2
grafanagrafana
5.0.0:beta3
grafanagrafana
5.0.0:beta4
grafanagrafana
5.0.0:beta5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grafana
bionic
dne
focal
dne
jammy
dne
trusty
ignored
xenial
needed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grafana
RHEL 9
0:9.2.10-7.el9_3
fixed