CVEFinder.io

CVE-2022-31123

🔶 medium
🔍 Scan for this CVE
Summary

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

CVSS Score
6.1
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2022-10-13
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 38.9% of all 328,009 vulnerabilities in our database.

#200,536
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Apr 23, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2024-11-21
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
CWE IDs (Weakness Types)

📦 Affected Products 3

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-28374 🔶 medium 4.3 0.0 Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t... 2026-05-13
CVE-2026-28376 🔶 medium 6.5 0.0 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req... 2026-05-13
CVE-2026-28379 🔶 medium 6.5 0.0 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur... 2026-05-13
CVE-2026-28380 🔶 medium 6.5 0.0 Any Editor could delete any snapshot, even if they have no access to read or write them. 2026-05-13
CVE-2026-28383 🔶 medium 6.5 0.0 A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b... 2026-05-13
CVE-2026-33376 ⚠️ high 7.4 0.0 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl... 2026-05-13
These CVEs affect the same products