Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-39307

21
FAUCET Score

CVE-2022-39307 is a Grafana information disclosure vulnerability affecting versions prior to 9.2.4 and 8.5.15. It allows unauthenticated users to determine if a username or email exists by observing the "user not found" message in the JSON response when attempting a password reset. This medium-severity vulnerability (CVSS 5.3) has a low impact on confidentiality, as it only leaks user existence. There is no known active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
< 8.5.15CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.2.4CPE matchmatch criteria
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.7MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.2
Impact Score
5.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.70%
Probability of exploitation in next 30 days
EPSS Percentile
49.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0070 is in the 31st percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 9.2.4
gopatch availablevia ghsa
Product: github.com/grafana/grafanaFixed in: 8.5.15
nodejspatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana-0:9.2.10-7.el9_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 6.1Fixed in: rhceph/rhceph-6-dashboard-rhel9:6-75
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 5Fixed in: rhceph/rhceph-5-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: rhceph/rhceph-4-dashboard-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/acm-grafana-rhel8

Vendor Advisories (8)

goGHSA-3p62-42x7-gxg5high

Grafana User enumeration via forget password

May 14, 2024
redhatCVE-2022-39307Moderate

grafana: User enumeration via forget password

Nov 8, 2022
zimbrallm-zimbra-d9aef90a9b97b34aMEDIUM

Information Disclosure in Password Reset in Grafana

Nov 8, 2022
kenticollm-kentico-06c43fcdfd91cbb0MEDIUM

Information Disclosure in Password Reset in Grafana

Nov 8, 2022
chainsafellm-chainsafe-6c62702f2971c77bMEDIUM

Information Disclosure in Password Reset in Grafana

Nov 8, 2022
apollographqlllm-apollographql-8f6aaacf38143b82MEDIUM

Information Disclosure in Password Reset in Grafana

Nov 8, 2022
jenkinsllm-jenkins-5123d3d7c03582b1MEDIUM

Information Disclosure in Password Reset in Grafana

Nov 8, 2022
nodejsllm-nodejs-1b6a69a3cc1ec0caMEDIUM

Information Disclosure in Password Reset in Grafana

Nov 8, 2022

References

github.com / grafana/grafana/security/advisories/GHSA-3p62-42x7-gxg5
Vendor Advisory
security.netapp.com / advisory/ntap-20221215-0004
Third Party Advisory