#VU71566 Spoofing attack in Grafana - CVE-2022-39324
Published: January 26, 2023
Grafana
Grafana Labs
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to usage of a hidden originalUrl parameter in the shared dashboard. A remote attacker can trick the victim into opening a shared snapshot and click on the button in the Grafana web UI, which will redirect user to an attacker-controlled URL.