First published: Tue Jan 18 2022(Updated: )
An information-disclosure flaw was found in grafana. When a data source has the Forward OAuth Identity feature enabled, sending a query to that data source with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This flaw allows API token holders to retrieve data to which they may not be authorized.
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <0:7.5.15-3.el8 | 0:7.5.15-3.el8 |
redhat/grafana | <0:7.5.15-3.el9 | 0:7.5.15-3.el9 |
Grafana Grafana | >=7.2.0<7.5.13 | |
Grafana Grafana | >=8.0.0<8.3.4 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
redhat/grafana | <8.3.4 | 8.3.4 |
redhat/grafana | <7.5.13 | 7.5.13 |
go/github.com/grafana/grafana | >=8.0.0<8.3.4 | 8.3.4 |
go/github.com/grafana/grafana | >7.2.0<7.5.13 | 7.5.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-21673 is an information-disclosure flaw found in Grafana.
Grafana is an open-source platform for monitoring and observability.
In affected versions, when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user.
CVE-2022-21673 has a severity rating of medium (4 out of 10).
To fix CVE-2022-21673, update Grafana to version 8.3.4 or 7.5.13, depending on the affected version.