vulnerability
Ubuntu: (CVE-2022-23498): grafana vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:M/Au:S/C:C/I:C/A:P) | Feb 3, 2023 | Jun 26, 2025 | Aug 18, 2025 |
Severity
8
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:P)
Published
Feb 3, 2023
Added
Jun 26, 2025
Modified
Aug 18, 2025
Description
Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.
Solution
no-fix-ubuntu-package
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.