When query caching is enabled in Grafana users can query another users session
CVE-2022-23498
What is CVE-2022-23498?
Grafana, an open-source platform widely used for monitoring and observability, has a reported vulnerability related to its datasource query caching feature. When enabled, this caching inadvertently stores all request headers, including sensitive session identifiers such as grafana_session. This flaw allows malicious users who query a cached datasource to potentially hijack another user's session, compromising account integrity and privacy. To mitigate this issue, users are advised to disable datasource query caching. The vulnerability has been addressed in Grafana versions 9.2.10 and 9.3.4.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
grafana >= 8.3.0-beta1, < 9.2.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved