Bug 1207979 (CVE-2022-23498) - VUL-0: CVE-2022-23498: grafana: Use of Cache Containing Sensitive Information
Summary: VUL-0: CVE-2022-23498: grafana: Use of Cache Containing Sensitive Information
Status: RESOLVED INVALID
Alias: CVE-2022-23498
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Witek Bedyk
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/356139/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-02-07 09:27 UTC by Thomas Leroy
Modified: 2023-02-08 11:18 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2023-02-07 09:27:06 UTC
rh#2167266

Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can disable datasource query caching for all datasources. This issue has been patched in versions 9.2.10 and 9.3.4.

https://github.com/grafana/grafana/security/advisories/GHSA-2j8f-6whh-frc8

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2167266
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-23498
https://www.cve.org/CVERecord?id=CVE-2022-23498
https://github.com/grafana/grafana/security/advisories/GHSA-2j8f-6whh-frc8
Comment 1 Thomas Leroy 2023-02-07 09:27:37 UTC
Affected:
- SUSE:SLE-15-SP1:Update:Products:SES6:Update
- SUSE:SLE-15-SP2:Update
- SUSE:SLE-15:Update
Comment 3 Witek Bedyk 2023-02-08 11:18:10 UTC
Datasource query caching is available only in Grafana Enterprise and Grafana Cloud products. Open source Grafana is not affected.

https://github.com/grafana/grafana/security/advisories/GHSA-2j8f-6whh-frc8
https://grafana.com/docs/grafana/latest/administration/data-source-management/#query-caching