CVE-2022-31123
Grafana plugin signature bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.
Grafana es una plataforma de código abierto de observabilidad y visualización de datos. Las versiones anteriores a 9.1.8 y 8.5.14, son vulnerables a una omisión en la verificación de la firma del plugin. Un atacante puede convencer a un administrador del servidor para que descargue y ejecute con éxito un plugin malicioso a pesar de que los plugins sin firma no están permitidos. Las versiones 9.1.8 y 8.5.14 contienen un parche para este problema. Como mitigación, no instale plugins descargados de fuentes no confiables
A flaw was found in the Grafana web application, where it is possible to install plugins which are not digitally signed. An admin could install unsigned plugins, which may contain malicious code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-18 CVE Reserved
- 2022-10-13 CVE Published
- 2024-05-20 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-347: Improper Verification of Cryptographic Signature
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/grafana/grafana/releases/tag/v9.1.8 | Release Notes | |
https://security.netapp.com/advisory/ntap-20221124-0002 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/grafana/grafana/security/advisories/GHSA-rhxj-gh46-jvw8 | 2022-12-03 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-31123 | 2023-11-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2131147 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Grafana Search vendor "Grafana" | Grafana Search vendor "Grafana" for product "Grafana" | >= 7.0.0 < 8.5.14 Search vendor "Grafana" for product "Grafana" and version " >= 7.0.0 < 8.5.14" | - |
Affected
| ||||||
Grafana Search vendor "Grafana" | Grafana Search vendor "Grafana" for product "Grafana" | >= 9.0.0 < 9.1.8 Search vendor "Grafana" for product "Grafana" and version " >= 9.0.0 < 9.1.8" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | E-series Performance Analyzer Search vendor "Netapp" for product "E-series Performance Analyzer" | - | - |
Affected
|