#VU68557 Authentication bypass using an alternate path or channel in Grafana - CVE-2022-35957
Published: October 20, 2022
Grafana
Grafana Labs
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to the way Grafana handles authorization process when Auth proxy authentication is used. A remote user with admin privileges can authenticate as Server Admin by providing the username (or email) in a X-WEBAUTH-USER HTTP header.