REDHAT-BUG-2131149: Medium severity grafana labs grafana oss and enterprise vulnerability

Published Sep 30, 2022
·
Updated

CVE-2022-39229: Using email as a username can block other users from signing in

Currently, a user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username.

However, the login system allows users to log in with either username or email address. Since we allow a user to log in with either their username or email address, this creates an unusual behavior where user1 can register with one email address and user2 can register his username as user1’s email address.

This prevents user1 from logging into the application since user1 password won’t match with users2 email address. This is a moderate severity security issue because it can stop a user from logging into the system.

Affected versions: Grafana <= 9.1.x

Affected Software

1 affected component
Grafana Grafana<=9.1.x

Event History

Sep 30, 2022
Data Sourced
via Red Hat·05:51 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2131149?

The severity of REDHAT-BUG-2131149 is classified as moderate.

2

How do I fix REDHAT-BUG-2131149?

To resolve REDHAT-BUG-2131149, users should update to Grafana version 9.2.x or later.

3

Which software is affected by REDHAT-BUG-2131149?

REDHAT-BUG-2131149 affects Grafana versions up to 9.1.x.

4

Can using an email address as a username lead to issues in REDHAT-BUG-2131149?

Yes, using an email address as a username in REDHAT-BUG-2131149 can block other users from signing in.

5

What are the implications of REDHAT-BUG-2131149 for user account management?

REDHAT-BUG-2131149 can cause complications in user account management due to the restriction on unique usernames and email addresses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203