Bug 2167266 (CVE-2022-23498)

Summary: CVE-2022-23498 grafana: Use of Cache Containing Sensitive Information
Product: [Other] Security Response Reporter: Avinash Hanwate <ahanwate>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: amctagga, aoconnor, bniver, dfreiber, flucifre, gmeno, gparvin, grafana-maint, jburrell, jkurik, jwendell, mbenjamin, mhackett, nathans, njean, ovanders, owatkins, pahickey, rcernich, rogbas, sostapov, stcannon, teagle, vereddy, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: grafana 9.3.4, grafana 9.2.10 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the Grafana package. When data-source query caching is enabled, Grafana caches all headers, including `grafana_session.` As a result, any user that queries a data source where the caching is enabled can acquire another user’s session.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2167270, 2167271, 2167664, 2167665    
Bug Blocks: 2167256    

Description Avinash Hanwate 2023-02-06 05:16:53 UTC
Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

https://github.com/grafana/grafana/security/advisories/GHSA-2j8f-6whh-frc8

Comment 2 Sandipan Roy 2023-02-06 05:44:07 UTC
Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2167270]

Comment 9 errata-xmlrpc 2024-02-08 16:57:59 UTC
This issue has been addressed in the following products:

  Red Hat Ceph Storage 5.3

Via RHSA-2024:0746 https://access.redhat.com/errata/RHSA-2024:0746