CVE-2022-39307 is a Grafana information disclosure vulnerability affecting versions prior to 9.2.4 and 8.5.15. It allows unauthenticated users to determine if a username or email exists by observing the "user not found" message in the JSON response when attempting a password reset. This medium-severity vulnerability (CVSS 5.3) has a low impact on confidentiality, as it only leaks user existence. There is no known active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.5.15CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.2.4CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Grafana User enumeration via forget password
May 14, 2024grafana: User enumeration via forget password
Nov 8, 2022Information Disclosure in Password Reset in Grafana
Nov 8, 2022Information Disclosure in Password Reset in Grafana
Nov 8, 2022Information Disclosure in Password Reset in Grafana
Nov 8, 2022Information Disclosure in Password Reset in Grafana
Nov 8, 2022Information Disclosure in Password Reset in Grafana
Nov 8, 2022Information Disclosure in Password Reset in Grafana
Nov 8, 2022