Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana | Nov 14, 2022 | Feb 8, 2022 |
| Alpine Linux | — | Upgrade grafana | Aug 22, 2024 | Feb 8, 2022 |
| Centos_linux | — | Upgrade grafana-debuginfoUpgrade grafana | Nov 9, 2022 | Feb 8, 2022 |
| Freebsd | — | Upgrade grafana7Upgrade grafana8Upgrade grafana6 | Nov 4, 2022 | Feb 12, 2022 |
| Oracle_linux | — | Upgrade grafana | Nov 16, 2022 | Feb 8, 2022 |
| Redhat_linux | — | Upgrade grafanaUpgrade grafana-debuginfo | Nov 9, 2022 | Feb 8, 2022 |
| Rocky_linux | — | Upgrade grafana-debuginfoUpgrade grafana | Mar 12, 2024 | Feb 8, 2022 |
| Suse | — | Upgrade golang-github-prometheus-node_exporterUpgrade prometheus-postgres_exporterUpgrade grafanaUpgrade spacecmdUpgrade python3-rhnlib | Oct 26, 2022 | Feb 8, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub