vulnerability
Ubuntu: (CVE-2022-23498): grafana vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:M/Au:S/C:C/I:C/A:P) | Feb 3, 2023 | Jun 26, 2025 | Mar 27, 2026 |
Severity
8
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:P)
Published
Feb 3, 2023
Added
Jun 26, 2025
Modified
Mar 27, 2026
Description
Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.
Solution
no-fix-ubuntu-package
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.