Missing Authentication for Critical Function in Grafana Enterprise - CVE-2022-28660
Published: June 15, 2022
Vulnerability identifier: #VU64391
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-28660
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the querier component in Grafana Enterprise does not require authentication when X-Scope-OrgID is used. A remote attacker can trigger the vulnerability and execute arbitrary code on the target system.
Affected software
Grafana Enterprise
IBM Watson Machine Learning Accelerator
IBM Watson Machine Learning Accelerator
How to mitigate CVE-2022-28660
Install updates from vendor's website.
Grafana Enterprise - update to 1.4.0
IBM Watson Machine Learning Accelerator - update to 3.0.0
IBM Watson Machine Learning Accelerator - update to 3.0.0