CVE-2022-21703
published 2022-02-08CVE-2022-21703: Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.24%
80.8th percentile
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | grafana_grafana_pkg_web | >= 3.0-beta1 < 7.5.15 | 7.5.15 |
| github.com | grafana_grafana_pkg_web | >= 8.0.0 < 8.3.5 | 8.3.5 |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | >= 3.0.1 < 7.5.15 | 7.5.15 |
| grafana | grafana | >= 8.0.0 < 8.3.5 | 8.3.5 |
| netapp | e-series_performance_analyzer | < 3.0 | 3.0 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa8.8HIGH
osv8.8HIGH
vendor_oracle7.0HIGH
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grafana: CSRF vulnerability can lead to privilege escalation
vendor_redhat·2022-02-08·CVSS 6.3
CVE-2022-21703 [MEDIUM] CWE-352 grafana: CSRF vulnerability can lead to privilege escalation
grafana: CSRF vulnerability can lead to privilege escalation
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
A Cross-site request forgery (CSRF) vulnerability was found in Grafana. This flaw allows anonymous attackers to elevate their privileges by mounting cross-origin
Oracle
Oracle Oracle Communications Risk Matrix: Platform (PHP) — CVE-2021-21703
vendor_oracle·2022-01-15·CVSS 7.0
CVE-2021-21703 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (PHP) — CVE-2021-21703
Oracle Oracle Communications Risk Matrix: Platform (PHP) vulnerability
CVE: CVE-2021-21703
CVSS: 7.0
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2022 (JAN 2022)
OSV
linux-oracle-5.15 vulnerabilities
osv·2025-04-25·CVSS 7.8
CVE-2022-0995 linux-oracle-5.15 vulnerabilities
linux-oracle-5.15 vulnerabilities
Jann Horn discovered that the watch_queue event notification subsystem in
the Linux kernel contained an out-of-bounds write vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
escalate their privileges. (CVE-2022-0995)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- File systems infrastructure;
- NTFS3 file system;
- Ethernet bridge;
- Ethtool driver;
- IPv6 networking;
- Network traffic control;
- VMware vSockets driver;
(CVE-2025-21993, CVE-2025-21703, CVE-2024-50248, CVE-2025-21700,
CVE-2024-50256, CVE-2025-21701, CVE-2024-56651, CVE-2025-21756,
CVE-2024-26837
GHSA
Grafana Cross Site Request Forgery (CSRF)
ghsa·2024-02-01·CVSS 8.8
CVE-2022-21703 [HIGH] CWE-352 Grafana Cross Site Request Forgery (CSRF)
Grafana Cross Site Request Forgery (CSRF)
Today we are releasing Grafana 8.3.5 and 7.5.15. This patch release includes MEDIUM severity security fix for Cross Site Request Forgery for Grafana.
Release v.8.3.5, only containing security fixes:
- [Download Grafana 8.3.5](https://grafana.com/grafana/download/8.3.5)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-5/)
Release v.7.5.15, only containing security fixes:
- [Download Grafana 7.5.15](https://grafana.com/grafana/download/7.5.15)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-5-15/)
## CSRF ([CVE-2022-21703](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703))
### Summary
On Jan. 18, security researchers [jub0bs](https://twitter.com/jub0b
OSV
Grafana Cross Site Request Forgery (CSRF)
osv·2024-02-01·CVSS 8.8
CVE-2022-21703 [HIGH] Grafana Cross Site Request Forgery (CSRF)
Grafana Cross Site Request Forgery (CSRF)
Today we are releasing Grafana 8.3.5 and 7.5.15. This patch release includes MEDIUM severity security fix for Cross Site Request Forgery for Grafana.
Release v.8.3.5, only containing security fixes:
- [Download Grafana 8.3.5](https://grafana.com/grafana/download/8.3.5)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-3-5/)
Release v.7.5.15, only containing security fixes:
- [Download Grafana 7.5.15](https://grafana.com/grafana/download/7.5.15)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-5-15/)
## CSRF ([CVE-2022-21703](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21703))
### Summary
On Jan. 18, security researchers [jub0bs](https://twitter.com/jub0b
OSV
CVE-2022-21703: Grafana is an open-source platform for monitoring and observability
osv·2022-02-08·CVSS 8.8
CVE-2022-21703 [HIGH] CVE-2022-21703: Grafana is an open-source platform for monitoring and observability
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
No detection rules found.
No public exploits indexed.
HackerOne
monitoring.prow-canary.k8s.io is vulnerable to CVE-2022-21703 (Grafana 0-day)
hackerone·2024-06-25·CVSS 6.3
CVE-2022-21703 [MEDIUM] monitoring.prow-canary.k8s.io is vulnerable to CVE-2022-21703 (Grafana 0-day)
monitoring.prow-canary.k8s.io is vulnerable to CVE-2022-21703 (Grafana 0-day)
## Summary
Disclaimer: At the time of writing this report, [CVE-2022-21703][cve] is still a 0-day. Grafana plans to release a fix on Tuesday, February 1st, 2022.
`https://monitoring.prow-canary.k8s.io` runs a version of Grafana vulnerable to CVE-2022-21703. By leveraging a vulnerability like XSS or subdomain takeover on a [same-site origin][webdev-samesite], an anonymous attacker to mount a cross-origin-request-forgery attack to escalate his privileges on your Grafana instance. More information about this attack vector in https://jub0bs.com/posts/2021-01-29-great-samesite-confusion.
We have not been able to find the required XSS or subdomain takeover to complete the bug chain, but you shouldn't rule out that
HackerOne
0-day Cross Origin Request Forgery vulnerability in Grafana 8.x .
hackerone·2022-03-16·CVSS 6.3
[MEDIUM] 0-day Cross Origin Request Forgery vulnerability in Grafana 8.x .
0-day Cross Origin Request Forgery vulnerability in Grafana 8.x .
## Disclaimer
To triage, please note that this is still a 0-day that was alerted to Grafana already, in order to make sure the client is safe I report this issue now, please make sure to not spread it further or leak it, as the best interest is to let you be aware and safer from any potential attacks in the meantime.
## Description
@jub0bs and I have found a cross-origin request forgery attack issue in the Grafana instances hosted on the Aiven platforms (CVE-2022-21703, which is still a 0-Day CVE on Grafana) .
With the cross-origin request forgery attack it's possible for an attacker to successfully mount cross-origin request forgery attack against authenticated victims of other grafana instances hosted on `*.aivencloud.
https://github.com/grafana/grafana/pull/45083https://github.com/grafana/grafana/security/advisories/GHSA-cmf4-h3xc-jw8whttps://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/https://security.netapp.com/advisory/ntap-20220303-0005/https://github.com/grafana/grafana/pull/45083https://github.com/grafana/grafana/security/advisories/GHSA-cmf4-h3xc-jw8whttps://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/https://security.netapp.com/advisory/ntap-20220303-0005/
2022-02-08
Published