BIT-grafana-2022-23498

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2022-23498.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2022-23498
Aliases
Published
2024-03-06T10:57:55.176Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including grafana_session. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

Database specific
{
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:grafana:grafana:8.3.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:grafana:grafana:8.3.0:beta2:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.3.1
Fixed
9.2.10
Introduced
9.3.0
Fixed
9.3.4