Grafana account takeover via OAuth vulnerability
Published Jul 15, 2022
7.6
HIGHCVSS 4.0
EPSS 2.87%
Description
Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user will be able to log in to the target user's Grafana account. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch for this issue. As a workaround, concerned users can disable OAuth login to their Grafana instance, or ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address.
Affected products
-
- Version >= 5.3, < 8.3.10StatusaffectedConstraints-
- Version >= 8.4.0, < 8.4.10StatusaffectedConstraints-
- Version >= 8.5.0, < 8.5.9StatusaffectedConstraints-
- Version >= 9.0.0, < 9.0.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
Red Hat Ceph Storage 6.1
rhceph/rhceph-6-dashboard-rhel9:6-75
Fixed · RHSA-2023:3642
Red Hat Enterprise Linux 8
grafana-0:7.5.11-3.el8_6
Fixed · RHSA-2022:5717
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
grafana-0:6.2.2-9.el8_1
Fixed · RHSA-2022:5720
Red Hat Enterprise Linux 8.2 Extended Update Support
grafana-0:6.3.6-5.el8_2
Fixed · RHSA-2022:5719
Red Hat Enterprise Linux 8.4 Extended Update Support
grafana-0:7.3.6-5.el8_4
Fixed · RHSA-2022:5718
Red Hat Enterprise Linux 9
grafana-0:7.5.11-5.el9_0
Fixed · RHSA-2022:5716
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Not affected
Red Hat Ceph Storage 3
grafana
Affected
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat Storage 3
grafana
Affected
Red Hat build of Quarkus
grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 6.1 | rhceph/rhceph-6-dashboard-rhel9:6-75 | Fixed | RHSA-2023:3642 |
| Red Hat Enterprise Linux 8 | grafana-0:7.5.11-3.el8_6 | Fixed | RHSA-2022:5717 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | grafana-0:6.2.2-9.el8_1 | Fixed | RHSA-2022:5720 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | grafana-0:6.3.6-5.el8_2 | Fixed | RHSA-2022:5719 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | grafana-0:7.3.6-5.el8_4 | Fixed | RHSA-2022:5718 |
| Red Hat Enterprise Linux 9 | grafana-0:7.5.11-5.el9_0 | Fixed | RHSA-2022:5716 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 3 | grafana | Affected | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat Storage 3 | grafana | Affected | n/a |
| Red Hat build of Quarkus | grafana | Not affected | n/a |
github.com/grafana/grafana
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/grafana/grafana | 0 | not fixed |
Remediation
Red Hat mitigation
As a workaround, it is possible to disable any OAuth login or ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-31107 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2104367 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1698 Advisory
- https://github.com/advisories/GHSA-mx47-6497-3fv2 Advisory
- https://github.com/grafana/grafana/security/advisories/GHSA-mx47-6497-3fv2 x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://grafana.com/docs/grafana/next/release-notes/release-notes-8-4-10 x_refsource_MISCRelease NotesVendor Advisory
- https://grafana.com/docs/grafana/next/release-notes/release-notes-8-5-9 x_refsource_MISCRelease NotesVendor Advisory
- https://grafana.com/docs/grafana/next/release-notes/release-notes-9-0-3 x_refsource_MISCRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-31107
- https://security.netapp.com/advisory/ntap-20220901-0010 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-31107
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-31107 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2104367 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1698 | Advisory | |
| https://github.com/advisories/GHSA-mx47-6497-3fv2 | Advisory | |
| https://github.com/grafana/grafana/security/advisories/GHSA-mx47-6497-3fv2 | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://grafana.com/docs/grafana/next/release-notes/release-notes-8-4-10 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://grafana.com/docs/grafana/next/release-notes/release-notes-8-5-9 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://grafana.com/docs/grafana/next/release-notes/release-notes-9-0-3 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-31107 | ||
| https://security.netapp.com/advisory/ntap-20220901-0010 | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-31107 |
Change history (0)
No recorded changes yet.