First published: Fri Feb 04 2022(Updated: )
An IDOR (Insecure Direct Object Reference) vulnerability was found on Grafana Teams APIs. This flaw impacts the `/teams/:teamId`, `/teams/:search`, `/teams/:teamId/members` API endpoints and may allow an authenticated attacker to view unintended data by querying for the specific team ID or search for teams and see the total number of available teams (including for those teams where the user does not have access to). GitHub security advisory: <a href="https://github.com/grafana/grafana/security/advisories/GHSA-63g3-9jq3-mccv">https://github.com/grafana/grafana/security/advisories/GHSA-63g3-9jq3-mccv</a> Grafana blog post: <a href="https://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes/">https://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes/</a>
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Grafana Grafana | >=5.0.0<7.5.15 | |
Grafana Grafana | >=8.0.0<8.3.5 | |
Grafana Grafana | =5.0.0-beta1 | |
Grafana Grafana | =5.0.0-beta2 | |
Grafana Grafana | =5.0.0-beta3 | |
Grafana Grafana | =5.0.0-beta4 | |
Grafana Grafana | =5.0.0-beta5 | |
Netapp E-series Performance Analyzer | <3.0 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
redhat/grafana | <0:7.5.15-3.el8 | 0:7.5.15-3.el8 |
redhat/grafana | <0:7.5.15-3.el9 | 0:7.5.15-3.el9 |
redhat/grafana | <7.5.15 | 7.5.15 |
redhat/grafana | <8.3.5 | 8.3.5 |
go/github.com/grafana/grafana | >=8.0.0<8.3.5 | 8.3.5 |
go/github.com/grafana/grafana | >=5.0.0-beta1<7.5.15 | 7.5.15 |
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21713 is an Insecure Direct Object Reference (IDOR) vulnerability found on Grafana Teams APIs.
The severity of CVE-2022-21713 is medium with a CVSS score of 4.3.
Affected versions of Grafana are 5.0.0-beta1 to 8.3.5 and 7.5.15-3.el8 to 7.5.15-3.el9.
CVE-2022-21713 allows an authenticated attacker to view unintended data by querying specific team IDs on Grafana.
To fix CVE-2022-21713, upgrade Grafana to version 7.5.15-3.el8 or 7.5.15-3.el9.