Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-10-13T00:00:00.000Z

Updated: 2025-04-23T16:50:57.182Z

Reserved: 2022-05-18T00:00:00.000Z

Link: CVE-2022-31130

cve-icon Vulnrichment

Updated: 2024-08-03T07:11:39.569Z

cve-icon NVD

Status : Modified

Published: 2022-10-13T23:15:09.637

Modified: 2024-11-21T07:03:57.583

Link: CVE-2022-31130

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-10-14T00:00:00Z

Links: CVE-2022-31130 - Bugzilla