=================================================================== CERT-Renater Note d'Information No. 2022/VULN385 _____________________________________________________________________ DATE : 14/10/2022 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Grafana versions prior to 9.1.8, 8.5.14. ====================================================================https://github.com/grafana/grafana/security/advisories/GHSA-gj7m-853r-289r https://github.com/grafana/grafana/security/advisories/GHSA-x744-mm8v-vpgr https://github.com/grafana/grafana/security/advisories/GHSA-jv32-5578-pxjc https://github.com/grafana/grafana/security/advisories/GHSA-rhxj-gh46-jvw8 _____________________________________________________________________ Using email as a username can block other users from signing in Moderate vtorosyan published GHSA-gj7m-853r-289r Package No package listed Affected versions <= 9.+, <= 8.+ Patched versions 9.1.8, 8.5.14 Description Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-39229 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues. Release 9.2, latest release, also containing security fix: Download Grafana 9.2 Release 9.1.8, only containing security fix: Download Grafana 9.1.8 Release 8.5.14, only containing security fix: Download Grafana 8.5.14 Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure's Grafana as a service offering. Improper authentication - CVE-2022-39229 Summary On September 7 as a result of an internal security audit we have discovered a security vulnerability in Grafana basic authentication, related to the usage of username and email address. In Grafana, a user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. In addition, a user can have an email address as a username and Grafana login allows users to sign in with either username or email address. This creates an unusual behavior, where user_1 can register with one email address and user_2 can register their username as user_1’s email address. As a result, user_1 would be prevented to sign in Grafana, since user_1 password won’t match with users_2 email address. The CVSS score for this vulnerability is 4.3 Moderate (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). Impacted versions All installations for Grafana versions <=9.x, <=8.x Solutions and mitigations To fully address CVE-2022-39229 please upgrade your Grafana instances. Appropriate patches have been applied to Grafana Cloud. Reporting security issues If you think you have found a security vulnerability, please send a report to security@grafana.com. This address can be used for all of Grafana Labs' open source and commercial products (including, but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com). We can accept only vulnerability reports at this address. We would prefer that you encrypt your message to us by using our PGP key. The key fingerprint is F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA The key is available from keyserver.ubuntu.com. Security announcements We maintain a security category on our blog, where we will always post a summary, remediation, and mitigation details for any patch containing security fixes. You can also subscribe to our RSS feed. Severity Moderate 4.3/ 10 CVSS base metrics Attack vector Network Attack complexity Low Privileges required Low User interaction None Scope Unchanged Confidentiality None Integrity None Availability Low CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVE ID CVE-2022-39229 Weaknesses No CWEs _____________________________________________________________________ Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins Moderate vtorosyan published GHSA-x744-mm8v-vpgr Package github.com/grafana/grafana (Grafana) Affected versions > = v5.0.0-beta1 Patched versions 9.1.8, 8.5.14 Description Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-39201 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues. Release 9.2, latest release, also containing security fix: Download Grafana 9.2 Release 9.1.8, only containing security fix: Download Grafana 9.1.8 Release 8.5.14, only containing security fix: Download Grafana 8.5.14 Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure's Grafana as a service offering. CVE-2022-39201 Summary On September 7th as a result of an internal security audit we have discovered that Grafana could leak the authentication cookie of users to plugins. After further analysis the vulnerability impacts data source and plugin proxy endpoints under certain conditions. We believe that this vulnerability is rated at CVSS 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H) Impact The destination plugin could receive a Grafana authentication cookie of the user. Impacted versions All installations for Grafana versions >= v5.0.0-beta1 Solutions and mitigations To fully address CVE-2022-39201 please upgrade your Grafana instances. Appropriate patches have been applied to Grafana Cloud. Reporting security issues If you think you have found a security vulnerability, please send a report to security@grafana.com. This address can be used for all of Grafana Labs' open source and commercial products (including, but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com). We can accept only vulnerability reports at this address. We would prefer that you encrypt your message to us by using our PGP key. The key fingerprint is F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA The key is available from keyserver.ubuntu.com. Security announcements We maintain a security category on our blog, where we will always post a summary, remediation, and mitigation details for any patch containing security fixes. You can also subscribe to our RSS feed. Severity Moderate 6.8/ 10 CVSS base metrics Attack vector Network Attack complexity Low Privileges required High User interaction Required Scope Unchanged Confidentiality High Integrity High Availability High CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H CVE ID CVE-2022-39201 Weaknesses No CWEs _____________________________________________________________________ Data source and plugin proxy endpoints leaking authentication tokens to some destination plugins Moderate vtorosyan published GHSA-jv32-5578-pxjc Package github.com/grafana/grafana (Grafana) Affected versions <= 9.+, <= 8.+, <= 7.+ Patched versions 9.1.8, 8.5.14 Description Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-31130 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues. Release 9.2, latest release, also containing security fix: Download Grafana 9.2 Release 9.1.8, only containing security fix: Download Grafana 9.1.8 Release 8.5.14, only containing security fix: Download Grafana 8.5.14 Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure's Grafana as a service offering. CVE-2022-31130 Summary On June 26 a security researcher contacted Grafana Labs to disclose a vulnerability with the GitLab data source plugin that could leak the API key to GitLab. After further analysis the vulnerability impacts data source and plugin proxy endpoints with authentication tokens but under some conditions. We believe that this vulnerability is rated at CVSS 4.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) Impact The destination plugin could receive a Grafana authentication token of the user. Impacted versions All installations for Grafana versions <=9.x, <=8.x, <=7.x Solutions and mitigations To fully address CVE-2022-31130 please upgrade your Grafana instances. Appropriate patches have been applied to Grafana Cloud. As a workaround do not use API keys, JWT authentication or any HTTP Header based authentication. Reporting security issues If you think you have found a security vulnerability, please send a report to security@grafana.com. This address can be used for all of Grafana Labs' open source and commercial products (including, but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com). We can accept only vulnerability reports at this address. We would prefer that you encrypt your message to us by using our PGP key. The key fingerprint is F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA The key is available from keyserver.ubuntu.com. Security announcements We maintain a security category on our blog, where we will always post a summary, remediation, and mitigation details for any patch containing security fixes. You can also subscribe to our RSS feed. Severity Moderate 4.9/ 10 CVSS base metrics Attack vector Network Attack complexity Low Privileges required High User interaction None Scope Unchanged Confidentiality High Integrity None Availability None CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE ID CVE-2022-31130 Weaknesses CWE-200 _____________________________________________________________________ Plugin signature bypass Moderate vtorosyan published GHSA-rhxj-gh46-jvw8 Package github.com/grafana/grafana (Grafana) Affected versions <= 9.+, <= 8.+, <=7.+ Patched versions 9.1.8, 8.5.14 Description Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-31123 We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues. Release 9.2, latest release, also containing security fix: Download Grafana 9.2 Release 9.1.8, only containing security fix: Download Grafana 9.1.8 Release 8.5.14, only containing security fix: Download Grafana 8.5.14 Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure's Grafana as a service offering. CVE-2022-31123 Summary On July 4th as a result of an internal security audit we have discovered a bypass in the plugin signature verification by exploiting a versioning flaw. We believe that this vulnerability is rated at CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L). Impact An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Impacted versions All installations for Grafana versions <=9.x, <=8.x, <=7.x Solutions and mitigations To fully address CVE-2022-31123 please upgrade your Grafana instances. Appropriate patches have been applied to Grafana Cloud. Reporting security issues If you think you have found a security vulnerability, please send a report to security@grafana.com. This address can be used for all of Grafana Labs' open source and commercial products (including, but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com). We can accept only vulnerability reports at this address. We would prefer that you encrypt your message to us by using our PGP key. The key fingerprint is F988 7BEA 027A 049F AE8E 5CAA D125 8932 BE24 C5CA The key is available from keyserver.ubuntu.com. Security announcements We maintain a security category on our blog, where we will always post a summary, remediation, and mitigation details for any patch containing security fixes. You can also subscribe to our RSS feed. Severity Moderate 6.1/ 10 CVSS base metrics Attack vector Local Attack complexity Low Privileges required High User interaction Required Scope Unchanged Confidentiality High Integrity High Availability Low CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L CVE ID CVE-2022-31123 Weaknesses CWE-347 ========================================================+ CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =======================================================