Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-10-13T00:00:00

Updated: 2022-10-13T00:00:00

Reserved: 2022-05-18T00:00:00


Link: CVE-2022-31130

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-10-13T23:15:09.637

Modified: 2022-10-17T13:31:29.640


Link: CVE-2022-31130

JSON object: View

cve-icon Redhat Information

No data.