REDHAT-BUG-2131148: Medium severity grafana image renderer vulnerability
CVE-2022-39201: Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins
Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions.
Affected versions: Grafana <= 9.1.x
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2131148?
The severity of REDHAT-BUG-2131148 is classified as high due to the potential leakage of authentication cookies.
How do I fix REDHAT-BUG-2131148?
To fix REDHAT-BUG-2131148, upgrade Grafana to version 9.2.0 or later to mitigate the vulnerability.
Which versions of Grafana are affected by REDHAT-BUG-2131148?
Grafana versions up to and including 9.1.x are affected by REDHAT-BUG-2131148.
What is the impact of REDHAT-BUG-2131148?
The impact of REDHAT-BUG-2131148 is the potential exposure of user authentication cookies to unauthorized plugins.
Is there a workaround for REDHAT-BUG-2131148?
No official workaround is provided for REDHAT-BUG-2131148; upgrading to a secure version is recommended.