CVE-2022-39328: Grafana vulnerable to race condition allowing privilege escalation

Published Nov 8, 2022
·
Updated

Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.

Other sources

Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes critical security fixes for CVE-2022-39328.

Release 9.2.4, latest patch, also containing security fix:

- Download Grafana 9.2.4

Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering.

Privilege escalation

Summary

Internal security audit identified a race condition in the Grafana codebase, which allowed an unauthenticated user to query an arbitrary endpoint in Grafana. A race condition in the HTTP context creation could make a HTTP request being assigned the authentication/authorization middlewares of another call. Under heavy load it is possible that a call protected by a privileged middleware receives instead the middleware of a public query. As a result, an unauthenticated user can successfully query protected endpoints.

The CVSS score for this vulnerability is 9.8 Critical

Impact

Unauthenticated users can query arbitrary endpoints with malicious intent.

Impacted versions

All installations for Grafana versions >=9.2.x.

Solutions and mitigations

To fully address CVE-2022-39328, please upgrade your Grafana instances. Appropriate patches have been applied to Grafana Cloud.

Reporting security issues

If you think you have found a security vulnerability, please send a report to security@grafana.com. This address can be used for all of Grafana Labs' open source and commercial products (including, but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com). We can accept only vulnerability reports at this address. We would prefer that you encrypt your message to us by using our PGP key. The key fingerprint is

F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA

The key is available from keyserver.ubuntu.com.

Security announcements

We maintain a security category on our blog, where we will always post a summary, remediation, and mitigation details for any patch containing security fixes.

You can also subscribe to our RSS feed.

GitHub

Affected Software

2 affected componentsFixes available
go/github.com/grafana/grafana>=9.2.0<9.2.4
9.2.4
Grafana Grafana>=9.2.0<9.2.4

Event History

Nov 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
May 14, 2024
Advisory Published
via GitHub·10:26 PM

Frequently Asked Questions

1

What is CVE-2022-39328?

CVE-2022-39328 is a vulnerability in Grafana versions 9.2.0 to 9.2.3 that allows an unauthenticated user to query an administration endpoint under heavy load due to a race condition in the authentication middleware logic.

2

What is the severity of CVE-2022-39328?

CVE-2022-39328 has a severity rating of 8.1, which is classified as critical.

3

How does CVE-2022-39328 affect Grafana?

CVE-2022-39328 affects Grafana versions 9.2.0 to 9.2.3.

4

How can I fix CVE-2022-39328 in Grafana?

To fix CVE-2022-39328, upgrade Grafana to version 9.2.4 or later.

5

Where can I find more information about CVE-2022-39328?

You can find more information about CVE-2022-39328 in the following references: [GitHub Security Advisory](https://github.com/grafana/grafana/security/advisories/GHSA-vqc4-mpj8-jxch) and [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20221215-0003/).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203