[ALPINE:CVE-2022-35957] grafana vulnerability

Severity Medium
Affected Packages 7
Fixed Packages 7
CVEs 1

[From CVE-2022-35957] Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As a workaround deactivate auth proxy following the instructions at: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 x86_64
Affected pkg:apk/alpine/grafana?arch=x86_64&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 x86_64
Fixed pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 x86
Affected pkg:apk/alpine/grafana?arch=x86&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 x86
Fixed pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 s390x
Affected pkg:apk/alpine/grafana?arch=s390x&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 s390x
Fixed pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 ppc64le
Affected pkg:apk/alpine/grafana?arch=ppc64le&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 ppc64le
Fixed pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 armv7
Affected pkg:apk/alpine/grafana?arch=armv7&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 armv7
Fixed pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 armhf
Affected pkg:apk/alpine/grafana?arch=armhf&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 armhf
Fixed pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.16 alpine grafana = 8.5.13-r0 alpine-3.16 aarch64
Affected pkg:apk/alpine/grafana?arch=aarch64&distro=alpine-3.16 alpine grafana < 8.5.13-r0 alpine-3.16 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...