Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-10-13T00:00:00
Updated: 2024-08-03T07:11:39.569Z
Reserved: 2022-05-18T00:00:00
Link: CVE-2022-31130
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-13T23:15:09.637
Modified: 2024-11-21T07:03:57.583
Link: CVE-2022-31130
Redhat