CVE-2022-23498

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-23498
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-23498.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-23498
Aliases
Related
Published
2023-02-03T22:15:09Z
Modified
2025-02-18T21:40:45Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including grafana_session. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

References

Affected packages

Git / github.com/grafana/grafana

Affected ranges

Type
GIT
Repo
https://github.com/grafana/grafana
Events