CVE-2022-31107: Grafana account takeover via OAuth vulnerability

Published Jul 6, 2022
·
Updated

A flaw was found in Grafana. This flaw allows a malicious user with the authorization to log into a Grafana instance via a configured OAuth IdP to take over an existing Grafana account under certain conditions.

Other sources

Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that Grafana instance. This can occur when the malicious user is authorized to log in to Grafana via OAuth, the malicious user's external user id is not already associated with an account in Grafana, the malicious user's email address is not already associated with an account in Grafana, and the malicious user knows the Grafana username of the target user. If these conditions are met, the malicious user can set their username in the OAuth provider to that of the target user, then go through the OAuth flow to log in to Grafana. Due to the way that external and internal user accounts are linked together during login, if the conditions above are all met then the malicious user will be able to log in to the target user's Grafana account. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch for this issue. As a workaround, concerned users can disable OAuth login to their Grafana instance, or ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address.

It is possible for a malicious user who has the authorization to log into a grafana instance via an OAuth integration which provides a login name to take over the account of another user in that Grafana instance provided the following criteria are met: - the malicious user is authorized to log in to Grafana via OAuth - the malicious user's external user id is not already associated with an account in Grafana - the malicious user's email address is not already associated with an account in Grafana - the malicious user knows the Grafana username or email of the target user

Red Hat

Today we are releasing Grafana 8.3.10, 8.4.10, 8.5.9 and 9.0.3. This patch release includes a HIGH severity security fix for an Oauth takeover vulnerability in Grafana.

Release v.9.0.3, containing this security fix and other patches:

- Download Grafana 9.0.3 - Release notes

Release v.8.5.9, containing this security fix and other fixes:

- Download Grafana 8.5.9 - Release notes

Release v.8.4.10, containing this security fix and other fixes:

- Download Grafana 8.4.10 - Release notes

Release v.8.3.10, containing this security fix and other fixes:

- Download Grafana 8.3.10

Grafana account takeover via OAuth vulnerability (CVE-2022-31107)

Summary On June 27 the HTTPVoid team contacted Grafana Labs to disclose a Grafana account takeover via an OAuth vulnerability.

We believe that this vulnerability is rated at CVSS 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).

Impact It is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP to take over an existing Grafana account under some conditions.

Affected versions with HIGH severity All Grafana >=5.3 versions are affected by this vulnerability.

Solutions and mitigations

All installations after Grafana v5.3 should be upgraded as soon as possible.

As a workaround it is possible to disable any OAuth login or ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address.

Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana.

Timeline

Here is a detailed timeline starting from when we originally learned of the issue. All times in UTC.

2022-06-27 19:00 - Research submission of vulnerability report 2022-06-27 20:53 - Issue triaged, confirmed positive, and internal incident raised 2022-06-28 08:42 - Fix PR submitted and reviewed 2022-06-28 20:58 - All Grafana Cloud hosted Grafana instances patched 2022-07-05 07:14 - Customers informed under embargo 2022-07-14 02:00 - Public release

Acknowledgement

We would like to thank the HTTPVoid team for responsibly disclosing the vulnerability.

Reporting security issues

If you think you have found a security vulnerability, please send a report to security@grafana.com. This address can be used for all of Grafana Labs' open source and commercial products (including, but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com). We can accept only vulnerability reports at this address. We would prefer that you encrypt your message to us by using our PGP key. The key fingerprint is

F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA

The key is available from keyserver.ubuntu.com.

Security announcements

We maintain a security category on our blog, where we will always post a summary, remediation, and mitigation details for any patch containing security fixes.

You can also subscribe to our RSS feed.

GitHub

Affected Software

18 affected componentsFixes available
redhat/grafana<0:7.5.11-3.el8_6
0:7.5.11-3.el8_6
redhat/grafana<0:6.2.2-9.el8_1
0:6.2.2-9.el8_1
redhat/grafana<0:6.3.6-5.el8_2
0:6.3.6-5.el8_2
redhat/grafana<0:7.3.6-5.el8_4
0:7.3.6-5.el8_4
redhat/grafana<0:7.5.11-5.el9_0
0:7.5.11-5.el9_0
redhat/Grafana<9.0.3
9.0.3
redhat/Grafana<8.5.9
8.5.9
redhat/Grafana<8.4.10
8.4.10
redhat/Grafana<8.3.10
8.3.10
go/github.com/grafana/grafana>=9.0.0<9.0.3
9.0.3
go/github.com/grafana/grafana>=8.5.0<8.5.9
8.5.9
go/github.com/grafana/grafana>=8.4.0<8.4.10
8.4.10
go/github.com/grafana/grafana>=5.3<8.3.10
8.3.10
Grafana Grafana>=5.3.0<8.3.10
Grafana Grafana>=8.4.0<8.4.10
Grafana Grafana>=8.5.0<8.5.9
Grafana Grafana>=9.0.0<9.0.3
NetApp E-series Performance Analyzer

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 0:7.5.11-3.el8_6
  2. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 0:6.2.2-9.el8_1
  3. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 0:6.3.6-5.el8_2
  4. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 0:7.3.6-5.el8_4
  5. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 0:7.5.11-5.el9_0
  6. Upgrade

    Upgrade go/github.com/grafana/grafana to a version that resolves this vulnerability.

    Fixed in 9.0.3
  7. Upgrade

    Upgrade go/github.com/grafana/grafana to a version that resolves this vulnerability.

    Fixed in 8.5.9
  8. Upgrade

    Upgrade go/github.com/grafana/grafana to a version that resolves this vulnerability.

    Fixed in 8.4.10
  9. Upgrade

    Upgrade go/github.com/grafana/grafana to a version that resolves this vulnerability.

    Fixed in 8.3.10
  10. Upgrade

    Upgrade redhat/Grafana to a version that resolves this vulnerability.

    Fixed in 9.0.3
  11. Upgrade

    Upgrade redhat/Grafana to a version that resolves this vulnerability.

    Fixed in 8.5.9
  12. Upgrade

    Upgrade redhat/Grafana to a version that resolves this vulnerability.

    Fixed in 8.4.10
  13. Upgrade

    Upgrade redhat/Grafana to a version that resolves this vulnerability.

    Fixed in 8.3.10
  14. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.3.10
  15. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.4.10
  16. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.5.9
  17. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 9.0.3
  18. Configuration

    As a workaround, disable any OAuth login on the Grafana instance to prevent OAuth-based account takeover.

    Grafana OAuth login (OAuth authentication) = disable
  19. Configuration

    As a workaround, ensure that all users authorized to log in via OAuth have a corresponding user account in Grafana linked to their email address (so OAuth identity cannot be mapped to an unlinked/new account).

    Grafana OAuth-linked user accounts = ensure

Event History

Jul 6, 2022
Data Sourced
via Red Hat·04:34 AM
DescriptionSeverityAffected Software
Jul 14, 2022
CVE Published
12:00 AM
Jul 15, 2022
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
May 14, 2024
Advisory Published
via GitHub·10:22 PM

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the vulnerability ID of this Grafana flaw?

The vulnerability ID of this Grafana flaw is CVE-2022-31107.

2

What is Grafana?

Grafana is an open-source platform for monitoring and observability.

3

What versions of Grafana are affected by this vulnerability?

Versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10 of Grafana are affected by this vulnerability.

4

How can a malicious user exploit this vulnerability?

A malicious user with authorization can log into a Grafana instance via a configured OAuth IdP and take over the account of another user.

5

What is the severity of this vulnerability?

The severity of this vulnerability is high, with a CVSS (Common Vulnerability Scoring System) score of 7.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203