Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins
Published Oct 13, 2022
8.5
HIGHCVSS 4.0
EPSS 1.34%
Description
Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination plugin could receive a user's Grafana authentication cookie. Versions 9.1.8 and 8.5.14 contain a patch for this issue. There are no known workarounds.
Affected products
-
- Version >= 9.0.0, < 9.1.8StatusaffectedConstraints-
- Version >= v5.0.0-beta1, < 8.5.14StatusaffectedConstraints-
- Version
- ≥ 5.0.1 · < 8.5.14
- ≥ 9.0.0 · < 9.1.8
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
- 5.0.0
No data.
Red Hat Ceph Storage 6.1
rhceph/rhceph-6-dashboard-rhel9:6-75
Fixed · RHSA-2023:3642
Red Hat Enterprise Linux 9
grafana-0:9.2.10-7.el9_3
Fixed · RHSA-2023:6420
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel8
Will not fix
Red Hat Ceph Storage 3
grafana
Out of support scope
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Affected
Red Hat Enterprise Linux 8
grafana
Will not fix
Red Hat OpenShift Container Platform 3.11
openshift3/grafana
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-grafana
Not affected
Red Hat Storage 3
grafana
Out of support scope
Red Hat build of Quarkus
grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 6.1 | rhceph/rhceph-6-dashboard-rhel9:6-75 | Fixed | RHSA-2023:3642 |
| Red Hat Enterprise Linux 9 | grafana-0:9.2.10-7.el9_3 | Fixed | RHSA-2023:6420 |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel8 | Will not fix | n/a |
| Red Hat Ceph Storage 3 | grafana | Out of support scope | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | n/a |
| Red Hat Storage 3 | grafana | Out of support scope | n/a |
| Red Hat build of Quarkus | grafana | Not affected | n/a |
github.com/grafana/grafana
Go
Introduced 5.0.0-beta1+incompatible Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/grafana/grafana | 5.0.0-beta1+incompatible | not fixed |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-39201 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2131148 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1853 Advisory
- https://github.com/advisories/GHSA-x744-mm8v-vpgr Advisory
- https://github.com/grafana/grafana/commit/b571acc1dc130a33f24742c1f93b93216da6cf57 PatchThird Party Advisory
- https://github.com/grafana/grafana/commit/c658816f5229d17f877579250c07799d3bbaebc9 PatchThird Party Advisory
- https://github.com/grafana/grafana/releases/tag/v9.1.8 Third Party Advisory
- https://github.com/grafana/grafana/security/advisories/GHSA-x744-mm8v-vpgr Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-39201
- https://www.cve.org/CVERecord?id=CVE-2022-39201
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-39201 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2131148 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1853 | Advisory | |
| https://github.com/advisories/GHSA-x744-mm8v-vpgr | Advisory | |
| https://github.com/grafana/grafana/commit/b571acc1dc130a33f24742c1f93b93216da6cf57 | PatchThird Party Advisory | |
| https://github.com/grafana/grafana/commit/c658816f5229d17f877579250c07799d3bbaebc9 | PatchThird Party Advisory | |
| https://github.com/grafana/grafana/releases/tag/v9.1.8 | Third Party Advisory | |
| https://github.com/grafana/grafana/security/advisories/GHSA-x744-mm8v-vpgr | Third Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-39201 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-39201 |
Change history (0)
No recorded changes yet.