First published: Fri Feb 04 2022(Updated: )
A Cross-site request forgery (CSRF) vulnerability was found in Grafana. This flaw allows anonymous attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, editors or admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <0:7.5.15-3.el8 | 0:7.5.15-3.el8 |
redhat/grafana | <0:7.5.15-3.el9 | 0:7.5.15-3.el9 |
Grafana Grafana | >=3.0.1<7.5.15 | |
Grafana Grafana | >=8.0.0<8.3.5 | |
Grafana Grafana | =3.0.0-beta1 | |
Grafana Grafana | =3.0.0-beta2 | |
Grafana Grafana | =3.0.0-beta3 | |
Grafana Grafana | =3.0.0-beta4 | |
Grafana Grafana | =3.0.0-beta5 | |
Grafana Grafana | =3.0.0-beta6 | |
Grafana Grafana | =3.0.0-beta7 | |
Netapp E-series Performance Analyzer | <3.0 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
redhat/grafana | <7.5.15 | 7.5.15 |
redhat/grafana | <8.3.5 | 8.3.5 |
go/github.com/grafana/grafana/pkg/web | >=8.0.0<8.3.5 | 8.3.5 |
go/github.com/grafana/grafana/pkg/web | >=3.0-beta1<7.5.15 | 7.5.15 |
Please refer to the Grafana upstream advisory for possible workarounds for this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21703 is a cross-site request forgery (CSRF) vulnerability found in Grafana, an open-source platform for monitoring and observability.
CVE-2022-21703 allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users, such as Editors.
The severity of CVE-2022-21703 is medium, with a CVSS score of 6.8.
Grafana versions up to and including 7.5.15 and versions up to and including 8.3.5 are affected by CVE-2022-21703.
To fix CVE-2022-21703, you need to upgrade your Grafana installation to version 7.5.16 or 8.3.6, which contain the security fixes.