Description
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1393 | Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to unauthenticated users and introduces a security risk. This issue has been patched in 9.2.4 and backported to 8.5.15. There are no known workarounds. |
Github GHSA |
GHSA-3p62-42x7-gxg5 | Grafana User enumeration via forget password |
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-28T04:55:23.388Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39307
Updated: 2024-08-03T12:00:44.036Z
Status : Modified
Published: 2022-11-09T23:15:12.617
Modified: 2024-11-21T07:18:00.080
Link: CVE-2022-39307
OpenCVE Enrichment
No data.
EUVD
Github GHSA