Cross site scripting in Grafana proxy
Published Feb 8, 2022
6.8
MEDIUMCVSS 3.1
EPSS 2.34%
Description
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource for a specific Grafana instance or either set up its own public service and instruct anyone to set it up in their Grafana instance. To be impacted, all of the following must be applicable. For the data source proxy: A Grafana HTTP-based datasource configured with Server as Access Mode and a URL set, the attacker has to be in control of the HTTP server serving the URL of above datasource, and a specially crafted link pointing at the attacker controlled data source must be clicked on by an authenticated user. For the plugin proxy: A Grafana HTTP-based app plugin configured and enabled with a URL set, the attacker has to be in control of the HTTP server serving the URL of above app, and a specially crafted link pointing at the attacker controlled plugin must be clocked on by an authenticated user. For the backend plugin resource: An attacker must be able to navigate an authenticated user to a compromised plugin through a crafted link. Users are advised to update to a patched version. There are no known workarounds for this vulnerability.
Affected products
-
Affected
- ≥ 2.0.0-beta1, < 7.5.15
- ≥ 8.0.0, < 8.3.5
Configuration 1
Configuration 2
- < 3.0
Configuration 3
- 34
- 35
- 36
No data.
Red Hat Enterprise Linux 8
grafana-0:7.5.15-3.el8
Fixed · RHSA-2022:7519
Red Hat Enterprise Linux 9
grafana-0:7.5.15-3.el9
Fixed · RHSA-2022:8057
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.1
openshift-service-mesh/grafana-rhel8
Affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Affected
Red Hat 3scale API Management Platform 2
3scale-operator-bundle-container
Not affected
Red Hat 3scale API Management Platform 2
3scale-operator-container
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/grafana-dashboard-loader-rhel8
Affected
Red Hat Ceph Storage 3
grafana
Out of support scope
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Will not fix
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Affected
Red Hat OpenShift GitOps
openshift-gitops-1/gitops-rhel8-operator
Not affected
Red Hat Storage 3
grafana
Will not fix
Red Hat build of Quarkus
grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | grafana-0:7.5.15-3.el8 | Fixed | RHSA-2022:7519 |
| Red Hat Enterprise Linux 9 | grafana-0:7.5.15-3.el9 | Fixed | RHSA-2022:8057 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.1 | openshift-service-mesh/grafana-rhel8 | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-operator-bundle-container | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-operator-container | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/grafana-dashboard-loader-rhel8 | Affected | n/a |
| Red Hat Ceph Storage 3 | grafana | Out of support scope | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Will not fix | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/gitops-rhel8-operator | Not affected | n/a |
| Red Hat Storage 3 | grafana | Will not fix | n/a |
| Red Hat build of Quarkus | grafana | Not affected | n/a |
github.com/grafana/grafana
Go
Introduced 2.0.0-beta1 Fixed 7.5.15github.com/grafana/grafana
Go
Introduced 8.0.0 Fixed 8.3.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/grafana/grafana | 2.0.0-beta1 | 7.5.15 |
| Go | github.com/grafana/grafana | 8.0.0 | 8.3.5 |
Remediation
Red Hat mitigation
Please refer to the Grafana upstream advisory for possible workarounds for this issue.
References (16)
- https://access.redhat.com/security/cve/CVE-2022-21702 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2050648 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1857 Advisory
- https://github.com/advisories/GHSA-xc3p-28hw-q24g Advisory
- https://github.com/grafana/grafana/commit/27726868b3d7c613844b55cd209ca93645c99b85 x_refsource_MISCPatchThird Party Advisory
- https://github.com/grafana/grafana/security/advisories/GHSA-xc3p-28hw-q24g x_refsource_CONFIRMExploitMitigationRelease NotesThird Party Advisory
- https://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes x_refsource_MISCRelease NotesVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ
- https://nvd.nist.gov/vuln/detail/CVE-2022-21702
- https://security.netapp.com/advisory/ntap-20220303-0005 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-21702
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub