CVE-2022-32276: High severity grafana labs grafana oss and enterprise vulnerability
Published Jun 17, 2022
·Updated
DISPUTED Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability.
Affected Software
1 affected component
Grafana Grafana=8.4.3
Event History
Jun 17, 2022
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
Description
Disputed
01:15 PM
Frequently Asked Questions
1
What is CVE-2022-32276?
CVE-2022-32276 is a vulnerability in Grafana 8.4.3 that allows unauthenticated access via a specific URI.
2
What is the severity of CVE-2022-32276?
The severity of CVE-2022-32276 is high with a CVSS score of 7.5.
3
How does CVE-2022-32276 affect Grafana?
CVE-2022-32276 affects Grafana 8.4.3, allowing unauthenticated access to certain URIs.
4
Is CVE-2022-32276 a vulnerability?
Yes, CVE-2022-32276 is considered a vulnerability in Grafana.
5
How can I fix CVE-2022-32276 in Grafana?
To fix CVE-2022-32276 in Grafana, it is recommended to update to a version that addresses the issue.