Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.
References
Link | Resource |
---|---|
https://github.com/grafana/grafana/security/advisories/GHSA-vqc4-mpj8-jxch | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20221215-0003/ | Third Party Advisory |
Configurations
Information
Published : 2022-11-08 15:15
Updated : 2023-02-15 19:14
NVD link : CVE-2022-39328
Mitre link : CVE-2022-39328
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
grafana
- grafana