CVEFinder.io

CVE-2022-31097

⚠️ high
🔍 Scan for this CVE
Summary

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use lega

Description

Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.

CVSS Score
7.3
High
EPSS Score
48.1
Exploit Probability
Published Date
2022-07-15
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 55.5% of all 328,009 vulnerabilities in our database.

#145,998
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Apr 23, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CWE IDs (Weakness Types)

📦 Affected Products 5

🔗 References 5

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-28374 🔶 medium 4.3 0.0 Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t... 2026-05-13
CVE-2026-28376 🔶 medium 6.5 0.0 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req... 2026-05-13
CVE-2026-28379 🔶 medium 6.5 0.0 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur... 2026-05-13
CVE-2026-28380 🔶 medium 6.5 0.0 Any Editor could delete any snapshot, even if they have no access to read or write them. 2026-05-13
CVE-2026-28383 🔶 medium 6.5 0.0 A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b... 2026-05-13
CVE-2026-33376 ⚠️ high 7.4 0.0 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl... 2026-05-13
These CVEs affect the same products