Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31097

65
FAUCET Score

CVE-2022-31097 is a stored cross-site scripting (XSS) vulnerability affecting Grafana versions 8.x and 9.x prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10, specifically within its Unified Alerting feature. This high-severity vulnerability (CVSS 8.7) allows an authenticated editor to escalate privileges to administrator by tricking an admin into clicking a malicious link. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the high EPSS score suggests a notable probability of future exploitation. Patches are available in versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10, and workarounds include disabling alerting or using legacy alerting.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.0.0, < 8.3.10CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 8.4.0, < 8.4.10CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 8.5.0, < 8.5.9CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.3CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
68.60%
Probability of exploitation in next 30 days
EPSS Percentile
99.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.6860 is in the 99th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.0.3
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.5.9
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.4.10
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.3.10
nodejspatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 6.1Fixed in: rhceph/rhceph-6-dashboard-rhel9:6-75
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana
redhatno patchvia redhat_api
Product: Red Hat Storage 3Fixed in: grafana
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 5Fixed in: rhceph/rhceph-5-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: rhceph/rhceph-4-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 3Fixed in: grafana
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh-grafana

Vendor Advisories (8)

goGHSA-vw7q-p2qg-4m5fmedium

Grafana Stored Cross-site Scripting in Unified Alerting

May 14, 2024
redhatCVE-2022-31097Important

grafana: stored XSS vulnerability

Jul 14, 2022
zimbrallm-zimbra-a012d3d82aeae862HIGH

XSS in Unified Alerting in Grafana

Jul 14, 2022
kenticollm-kentico-711cc972ffec1fecHIGH

XSS in Unified Alerting in Grafana

Jul 14, 2022
chainsafellm-chainsafe-a3a4642d3442c077HIGH

XSS in Unified Alerting in Grafana

Jul 14, 2022
apollographqlllm-apollographql-54be07817a8a84c1HIGH

XSS in Unified Alerting in Grafana

Jul 14, 2022
jenkinsllm-jenkins-e34b8f7e3d00b697HIGH

XSS in Unified Alerting in Grafana

Jul 14, 2022
nodejsllm-nodejs-1bcbe87d63012b80HIGH

XSS in Unified Alerting in Grafana

Jul 14, 2022

References

github.com / grafana/grafana/security/advisories/GHSA-vw7q-p2qg-4m5f
Release NotesThird Party Advisory
grafana.com / docs/grafana/latest/release-notes/release-notes-8-5-9
Release NotesVendor Advisory
grafana.com / docs/grafana/latest/release-notes/release-notes-9-0-3
Release NotesVendor Advisory
grafana.com / docs/grafana/next/release-notes/release-notes-8-4-10
Release NotesVendor Advisory
security.netapp.com / advisory/ntap-20220901-0010
Third Party Advisory