CVE-2022-39324

Aliases:GHSA-4724-7jwc-3fpwBIT-grafana-2022-39324GO-2024-2867CGA-2f72-vmj9-p9q4CGA-2hpx-j9rj-7rmpCGA-3f5f-9g86-7m8pCGA-494m-f967-c934CGA-498g-5hw6-gfxqCGA-4c38-pj6p-3rwgCGA-5hx5-82gf-m4v9CGA-63h2-5gfv-w5ghCGA-67ff-hw3r-xgmqCGA-6jw8-ch29-gjr8CGA-6qfq-w9r5-53c6CGA-74rf-r6pm-wggpCGA-779h-m6m3-v9g3CGA-77w4-37qp-6c9mCGA-835x-v38v-x89hCGA-87p8-pg36-9xxmCGA-f859-p487-5pf9CGA-f9hc-x98p-vw6cCGA-fc8p-5xrw-7qj7CGA-g5v5-83m3-5gxmCGA-gq62-hxwp-5f99CGA-h8c6-99jg-vr3xCGA-hvqp-8fp7-cf2wCGA-j5rw-f6gf-3jpqCGA-j7cx-h8x9-w8fvCGA-m7wp-2f3h-xmg3CGA-pvhw-8jr3-pjf7CGA-pxjx-77j8-2cvpCGA-q674-724j-6j2hCGA-r6hq-6x4h-mhp2CGA-v3cj-447j-9q97CGA-vcpv-v567-35fpCGA-vm2r-q9gv-rhffCGA-w5j5-6ggv-gcfqCGA-wr79-8rw7-7fh8CGA-x49w-p3m3-89xfCGA-x5cw-93c9-m3r6CGA-x68g-gfw4-7cc3CGA-x9q8-753c-6jcjCGA-xr3m-w2xq-xv7q
Modified
Published: 27 Jan 2023, 22:42
Last modified:28 Jan 2026, 04:55

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.7 MEDIUM
v3.1 (cve.org)
EPSS Score
0.83% LOW
1% probability +0.73%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Jan 2023, 22:42
Published
Vulnerability first disclosed
28 Jan 2026, 04:55
Last Modified
Vulnerability information updated

Description

Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the regular web interface delivered by the trusted Grafana server. The `Open original dashboard` button no longer points to the to the real original dashboard but to the attacker’s injected URL. This issue is fixed in versions 8.5.16 and 9.2.8.

CVSS Metrics

  • v4.0MEDIUMScore: 5.3CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L
  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
  • v3.1LOWScore: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.83% Percentile: 56%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • chainguardgrafana-fips-11.6

    < 0

  • chainguardgrafana-fips-12.0

    < 12.0.10-r6

  • chainguardgrafana-fips-12.1

    < 12.1.10.01-r3

  • chainguardgrafana-fips-12.2

    < 0

  • chainguardgrafana-fips-12.3

    < 0

  • chainguardgrafana-fips-12.4

    < 0

  • chainguardgrafana-fips-13.0

    < 0

  • chainguardgrafana-fips-13.1

    < 13.1.0-r0

  • github.com/grafanagrafana

    all | ≥ 9.0.0, < 9.2.8 | < 8.5.16

  • grafanagrafana

    < 8.5.16 | ≥ 9.0.0, < 9.2.8

References (9)