Back

HIGH

Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

Published Oct 13, 2022

Description

Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 13, 2022
Updated Apr 23, 2025
Reserved Sep 2, 2022
CISA Vulnrichment
Updated Apr 23, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 14, 2022
ENISA EUVD
Assigner GitHub_M
Published Oct 13, 2022
Updated Apr 23, 2025
Exploited since n/a
EUVD-2024-1853 GHSA-X744-MM8V-VPGR