When query caching is enabled in Grafana users can query another users session
CVE-2022-23498

7.1HIGH

Key Information:

Vendor
Grafana
Status
Vendor
CVE Published:
3 February 2023

Summary

Grafana, an open-source platform widely used for monitoring and observability, has a reported vulnerability related to its datasource query caching feature. When enabled, this caching inadvertently stores all request headers, including sensitive session identifiers such as grafana_session. This flaw allows malicious users who query a cached datasource to potentially hijack another user's session, compromising account integrity and privacy. To mitigate this issue, users are advised to disable datasource query caching. The vulnerability has been addressed in Grafana versions 9.2.10 and 9.3.4.

Affected Version(s)

grafana >= 8.3.0-beta1, < 9.2.10

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.