Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-10-13T00:00:00

Updated: 2024-08-03T07:11:39.569Z

Reserved: 2022-05-18T00:00:00

Link: CVE-2022-31130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-13T23:15:09.637

Modified: 2022-10-17T13:31:29.640

Link: CVE-2022-31130

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-10-14T00:00:00Z

Links: CVE-2022-31130 - Bugzilla