Grafana -- Privilege escalation

Affected packages
2.1.0 <= grafana < 8.5.13
9.0.0 <= grafana < 9.0.9
9.1.0 <= grafana < 9.1.6
7.0 <= grafana7
8.0.0 <= grafana8 < 8.5.13
9.0.0 <= grafana9 < 9.0.9
9.1.0 <= grafana9 < 9.1.6


VuXML ID 95e6e6ca-3986-11ed-8e0c-6c3be5272acd
Discovery 2022-08-09
Entry 2022-09-21

Grafana Labs reports:

On August 9 an internal security review identified a vulnerability in the Grafana which allows an escalation from Admin privileges to Server Admin when Auth proxy authentication is used.

Auth proxy allows to authenticate a user by only providing the username (or email) in a X-WEBAUTH-USER HTTP header: the trust assumption is that a front proxy will take care of authentication and that Grafana server is publicly reachable only with this front proxy.

Datasource proxy breaks this assumption:

The CVSS score for this vulnerability is 6.6 Moderate (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).


CVE Name CVE-2022-35957