Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-21703 Details

Description

Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/grafana/grafana/pull/45083 CVEIssue TrackingPatchThird Party Advisory
https://github.com/grafana/grafana/security/advisories/GHSA-cmf4-h3xc-jw8w CVEMitigationRelease NotesThird Party Advisory
https://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes/ CVEMitigationRelease NotesVendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/ CVE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/ CVE

see all 14 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-352Cross-Site Request Forgery (CSRF)[email protected]
CWE-352Cross-Site Request Forgery (CSRF)[email protected]

Affected Products

ProductVersions
grafana grafana
>= 3.0.1, < 7.5.15
>= 8.0.0, < 8.3.5
3.0.0 beta1
3.0.0 beta2
3.0.0 beta3

CPE

  • cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta1:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta2:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta3:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta4:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta5:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta6:*:*:*:*:*:*
  • cpe:2.3:a:grafana:grafana:3.0.0:beta7:*:*:*:*:*:*

Remediation

  • No remediation found in references.
netapp e-series performance analyzer
< 3.0

CPE

  • cpe:2.3:a:netapp:e-series_performance_analyzer:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
34
35
36

CPE

  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-21703
NVD Published Date:
Feb 8, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2022-21703 Details - Not Deferred