CVE-2022-31123
Aliases:GHSA-rhxj-gh46-jvw8BIT-grafana-2022-31123GO-2024-2855CGA-2qq5-m5m3-9fwmCGA-2rcj-6c45-vqf7CGA-3f35-xwpr-3r5wCGA-3p45-gwpc-683hCGA-58gr-vwv7-gg88CGA-5fh4-fh98-9g37CGA-5j2g-8v2f-6f4pCGA-6h9j-vgfm-rq3qCGA-6rmp-9gfq-g4r8CGA-6v79-8j5x-wx5mCGA-6wf7-7q56-8v87CGA-7hc2-v4hq-mhwpCGA-7m6x-7vqf-cmppCGA-8779-w685-r77qCGA-894m-8cw3-mr7fCGA-8p7c-36fc-f6j9CGA-92j6-q8hw-wx2gCGA-93gc-wh65-gv63CGA-95jh-86mq-q28hCGA-9xrp-w5q8-gmv9CGA-c79q-pgcx-h7x4CGA-ccpp-hvxh-r788CGA-g529-r43f-gcvxCGA-h329-2whx-9q7wCGA-j3r5-qxx2-7v3vCGA-j62r-jxx5-m2crCGA-j64w-f6gv-x4j6CGA-jhwj-m66g-6vq6CGA-jvgc-jcmw-c4v4CGA-p7pm-qmm5-mrqpCGA-q4x5-73xv-8xc4CGA-qc65-gfvc-9pfvCGA-vjqm-fhh8-233gCGA-w587-4f24-g559CGA-w8v2-xc9c-jfm7CGA-whfm-2g5p-g8cvCGA-ww45-6cwm-mh38CGA-ww98-x899-jx3vCGA-xhjj-2gv5-gvmqCGA-xrfq-r6cm-rq64
Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 13 Oct 2022, 00:00
Last modified:28 Jan 2026, 04:55
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.27% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Oct 2022, 00:00
Published
Vulnerability first disclosed
28 Jan 2026, 04:55
Last Modified
Vulnerability information updated
Description
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.
CVSS Metrics
- v4.0•HIGH•Score: 8.4CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
- v3.1•MEDIUM•Score: 6.1CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.27%• Percentile: 19%
Techniques & Countermeasures
- CWE-347•Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Affected Systems
- chainguard•grafana-fips-11.6
< 0
- chainguard•grafana-fips-12.0
< 12.0.10-r6
- chainguard•grafana-fips-12.1
< 12.1.10.01-r3
- chainguard•grafana-fips-12.2
< 0
- chainguard•grafana-fips-12.3
< 0
- chainguard•grafana-fips-12.4
< 0
- chainguard•grafana-fips-13.0
< 0
- chainguard•grafana-fips-13.1
< 13.1.0-r0
- github.com/grafana•grafana
all | ≥ 9.0.0, < 9.1.8 | ≥ 7.0.0, < 8.5.14
- grafana•grafana
< 8.5.14 | ≥ 7.0.0, < 8.5.14 | ≥ 9.0.0, < 9.1.8
- netapp•e-series_performance_analyzer
na
References (7)
- https://github.com/grafana/grafana/security/advisories/GHSA-rhxj-gh46-jvw8
- https://github.com/grafana/grafana/releases/tag/v9.1.8
- https://security.netapp.com/advisory/ntap-20221124-0002/
- https://nvd.nist.gov/vuln/detail/CVE-2022-31123
- https://github.com/grafana/grafana
- https://security.netapp.com/advisory/ntap-20221124-0002
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31123.json