445
VMScore

CVE-2022-32276

Published: 17/06/2022 Updated: 11/04/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grafana grafana 8.4.3

Github Repositories

grafana 8.4.3 (b7d2911ca)

grafana grafana 843 (b7d2911ca), works on 855 ( tested for @TheFrenchGhosty ) First point - CVE-2022-32276 Unauthenticated and authenticated users can send a false request for snapshot query using random key parameters, having access to the system dashboard area by going through the login page • Rated version: 843 (b7d2911ca) • Access the system the user is dir