REDHAT-BUG-2131147: Medium severity grafana labs grafana oss and enterprise vulnerability
CVE-2022-31123: Plugin signature bypass It is possible to bypass plugin signatures by exploiting a versioning flaw in Grafana. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins <https://go.grafana.com/MzU2LVlGRy0zODkAAAGHKffeRdXtITNJ57jRLGNoDYneVd-OEEcBdv-IjxVZkAZsJruum93h2vIohJ4utenGSY7smU=> are not allowed.
Affected versions: Grafana <= 9.1.x
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2131147?
The severity of REDHAT-BUG-2131147 is classified as high due to the potential for attackers to exploit the vulnerability to bypass plugin signatures.
How do I fix REDHAT-BUG-2131147?
To fix REDHAT-BUG-2131147, upgrade Grafana to version 9.2.x or later where the vulnerability has been patched.
What is the impact of REDHAT-BUG-2131147?
The impact of REDHAT-BUG-2131147 could allow an attacker to execute malicious plugins on a Grafana server, potentially leading to unauthorized access or system compromise.
Which versions of Grafana are affected by REDHAT-BUG-2131147?
Grafana versions up to and including 9.1.x are affected by REDHAT-BUG-2131147.
What are the potential exploits for REDHAT-BUG-2131147?
Potential exploits for REDHAT-BUG-2131147 involve tricking server administrators into installing malicious plugins that appear valid due to the versioning flaw.