When query caching is enabled in Grafana users can query another users session
CVE-2022-23498
7.1HIGH
Summary
Grafana, an open-source platform widely used for monitoring and observability, has a reported vulnerability related to its datasource query caching feature. When enabled, this caching inadvertently stores all request headers, including sensitive session identifiers such as grafana_session
. This flaw allows malicious users who query a cached datasource to potentially hijack another user's session, compromising account integrity and privacy. To mitigate this issue, users are advised to disable datasource query caching. The vulnerability has been addressed in Grafana versions 9.2.10 and 9.3.4.
Affected Version(s)
grafana >= 8.3.0-beta1, < 9.2.10
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved