First published: Thu Sep 22 2022(Updated: )
Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/grafana/grafana | >=9.1.0<9.1.6 | 9.1.6 |
go/github.com/grafana/grafana | >=9.0.0<9.0.9 | 9.0.9 |
go/github.com/grafana/grafana | >=8.5.0<8.5.13 | 8.5.13 |
Grafana Labs Grafana OSS and Enterprise | <8.5.13 | |
Grafana Labs Grafana OSS and Enterprise | >=9.0.0<9.0.9 | |
Grafana Labs Grafana OSS and Enterprise | >=9.1.0<9.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36062 is a vulnerability in Grafana versions prior to 8.5.13, 9.0.9, and 9.1.6 that allows privilege escalation on certain folders where Admin is the only used permission.
Grafana versions prior to 8.5.13, 9.0.9, and 9.1.6 are affected by CVE-2022-36062.
CVE-2022-36062 has a severity rating of 3.8 (high).
To fix CVE-2022-36062, upgrade your Grafana installation to version 8.5.13, 9.0.9, or 9.1.6 or later.
You can find more information about CVE-2022-36062 on the GitHub Security Advisory and NetApp Security Advisory.