CVE-2022-31123

Aliases:GHSA-rhxj-gh46-jvw8BIT-grafana-2022-31123GO-2024-2855CGA-2qq5-m5m3-9fwmCGA-2rcj-6c45-vqf7CGA-3f35-xwpr-3r5wCGA-3p45-gwpc-683hCGA-58gr-vwv7-gg88CGA-5fh4-fh98-9g37CGA-5j2g-8v2f-6f4pCGA-6h9j-vgfm-rq3qCGA-6rmp-9gfq-g4r8CGA-6v79-8j5x-wx5mCGA-6wf7-7q56-8v87CGA-7hc2-v4hq-mhwpCGA-7m6x-7vqf-cmppCGA-8779-w685-r77qCGA-894m-8cw3-mr7fCGA-8p7c-36fc-f6j9CGA-92j6-q8hw-wx2gCGA-93gc-wh65-gv63CGA-95jh-86mq-q28hCGA-9xrp-w5q8-gmv9CGA-c79q-pgcx-h7x4CGA-ccpp-hvxh-r788CGA-g529-r43f-gcvxCGA-h329-2whx-9q7wCGA-j3r5-qxx2-7v3vCGA-j62r-jxx5-m2crCGA-j64w-f6gv-x4j6CGA-jhwj-m66g-6vq6CGA-jvgc-jcmw-c4v4CGA-p7pm-qmm5-mrqpCGA-q4x5-73xv-8xc4CGA-qc65-gfvc-9pfvCGA-vjqm-fhh8-233gCGA-w587-4f24-g559CGA-w8v2-xc9c-jfm7CGA-whfm-2g5p-g8cvCGA-ww45-6cwm-mh38CGA-ww98-x899-jx3vCGA-xhjj-2gv5-gvmqCGA-xrfq-r6cm-rq64
Modified
Published: 13 Oct 2022, 00:00
Last modified:28 Jan 2026, 04:55

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.27% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Oct 2022, 00:00
Published
Vulnerability first disclosed
28 Jan 2026, 04:55
Last Modified
Vulnerability information updated

Description

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS Metrics

  • v4.0HIGHScore: 8.4CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.27% Percentile: 19%

Techniques & Countermeasures

  • CWE-347Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Systems

  • chainguardgrafana-fips-11.6

    < 0

  • chainguardgrafana-fips-12.0

    < 12.0.10-r6

  • chainguardgrafana-fips-12.1

    < 12.1.10.01-r3

  • chainguardgrafana-fips-12.2

    < 0

  • chainguardgrafana-fips-12.3

    < 0

  • chainguardgrafana-fips-12.4

    < 0

  • chainguardgrafana-fips-13.0

    < 0

  • chainguardgrafana-fips-13.1

    < 13.1.0-r0

  • github.com/grafanagrafana

    all | ≥ 9.0.0, < 9.1.8 | ≥ 7.0.0, < 8.5.14

  • grafanagrafana

    < 8.5.14 | ≥ 7.0.0, < 8.5.14 | ≥ 9.0.0, < 9.1.8

  • netappe-series_performance_analyzer

    na

References (7)