Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes moderate security fixes for CVE-2022-39307. We are also releasing security patches for Grafana 8.5.15 to fix these issues. Release 9.2.4, latest patch, also containing security fix: Download Grafana 9.2.4 Release 8.5.15, only containing security fix: Download Grafana 8.5.15 Appropriate patches have been applied to Grafana Cloud and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering. Username enumeration Summary When using the forget password on the login page, a POST request is made to the /api/user/password/sent-reset-email URL. When the username or email does not exist, a JSON response contains a “user not found” message. The CVSS score for this vulnerability is 5.3 Moderate Impact The impacted endpoint leaks information to unauthenticated users and introduces a security risk. Impacted versions All installations for Grafana versions Grafana <=9.x, <8.x Solutions and mitigations To fully address CVE-2022-39307, please upgrade your Grafana instances. Appropriate patches have been applied to Grafana Cloud. Reporting security issues If you think you have found a security vulnerability, please send a report to…Read More
Grafana User enumeration via forget password

