CVE-2022-31097 is a stored cross-site scripting (XSS) vulnerability affecting Grafana versions 8.x and 9.x prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10, specifically within its Unified Alerting feature. This high-severity vulnerability (CVSS 8.7) allows an authenticated editor to escalate privileges to administrator by tricking an admin into clicking a malicious link. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the high EPSS score suggests a notable probability of future exploitation. Patches are available in versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10, and workarounds include disabling alerting or using legacy alerting.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, < 8.3.10CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 8.4.0, < 8.4.10CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 8.5.0, < 8.5.9CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.0.3CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grafana Stored Cross-site Scripting in Unified Alerting
May 14, 2024grafana: stored XSS vulnerability
Jul 14, 2022XSS in Unified Alerting in Grafana
Jul 14, 2022XSS in Unified Alerting in Grafana
Jul 14, 2022XSS in Unified Alerting in Grafana
Jul 14, 2022XSS in Unified Alerting in Grafana
Jul 14, 2022XSS in Unified Alerting in Grafana
Jul 14, 2022XSS in Unified Alerting in Grafana
Jul 14, 2022