Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user's Grafana authentication token. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not use API keys, JWT authentication, or any HTTP Header based authentication.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-10-13T00:00:00.000Z
Updated: 2025-04-23T16:50:57.182Z
Reserved: 2022-05-18T00:00:00.000Z
Link: CVE-2022-31130

Updated: 2024-08-03T07:11:39.569Z

Status : Modified
Published: 2022-10-13T23:15:09.637
Modified: 2024-11-21T07:03:57.583
Link: CVE-2022-31130
