<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:21:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2167 — Moderate: grafana security and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2167</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)
* golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664)
* grafana: Escalation from admin to server admin when auth proxy is used (CVE-2022-35957)
* grafana: using email as a username can block other users from signing in (CVE-2022-39229)
* golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp; OpenTSDB.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters (CVE-2022-2880)
* golang: net/http: handle server errors after sending GOAWAY (CVE-2022-27664)
* grafana: Escalation from admin to server admin when auth proxy is used (CVE-2022-35957)
* grafana: using email as a username can block other users from signing in (CVE-2022-39229)
* golang: regexp/syntax: limit memory used by parsing regexps (CVE-2022-41715)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2167</guid>
    </item>
    <item>
      <title>bdu:2024-02618</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02618</link>
      <description>bdu:2024-02618</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02618</guid>
    </item>
    <item>
      <title>BIT-grafana-2022-39229 — Grafana users with email as a username can block other users from signing in</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2022-39229</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;#39;s login attempt by registering someone else&amp;#39;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;#39;s password won’t match with `user_2`&amp;#39;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;#39;s login attempt by registering someone else&amp;#39;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;#39;s password won’t match with `user_2`&amp;#39;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2022-39229</guid>
    </item>
    <item>
      <title>certfr-2022-avi-914 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer un contourne…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-914</link>
      <description>certfr-2022-avi-914</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-914</guid>
    </item>
    <item>
      <title>cnvd-2022-87932</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-87932</link>
      <description>cnvd-2022-87932</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-87932</guid>
    </item>
    <item>
      <title>EUVD-2026-233524</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233524</link>
      <description>EUVD-2026-233524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233524</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39229</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39229</link>
      <description>&lt;p&gt;Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;#39;s login attempt by registering someone else&amp;#39;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;#39;s password won’t match with `user_2`&amp;#39;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;#39;s login attempt by registering someone else&amp;#39;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;#39;s password won’t match with `user_2`&amp;#39;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39229</guid>
    </item>
    <item>
      <title>GHSA-gj7m-853r-289r — Grafana when using email as a username can block other users from signing in</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gj7m-853r-289r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-39229&lt;/p&gt;
&lt;p&gt;We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues.&lt;/p&gt;
&lt;p&gt;Release 9.2, latest release, also containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.2](https://grafana.com/grafana/download/9.2)&lt;/p&gt;
&lt;p&gt;Release 9.1.8, only containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.1.8](https://grafana.com/grafana/download/9.1.8)&lt;/p&gt;
&lt;p&gt;Release 8.5.14, only containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.5.14](https://grafana.com/grafana/download/8.5.14)&lt;/p&gt;
&lt;p&gt;Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure&amp;#39;s Grafana as a service offering.&lt;/p&gt;
&lt;p&gt;## Improper authentication - CVE-2022-39229&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On September 7 as a result of an internal security audit we have discovered a security vulnerability in Grafana basic authentication, related to the usage of username and email address.&lt;/p&gt;
&lt;p&gt;In Grafana, a user’s username and email address are unique fields, that means no other user can have the same username or email address as another user.&lt;/p&gt;
&lt;p&gt;In addition, a user can have an email address as a username and Grafana…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 9.2. Alongside with new features and other bug fixes, this release includes a Moderate severity security fix for CVE-2022-39229&lt;/p&gt;
&lt;p&gt;We are also releasing security patches for Grafana 9.1.8 and Grafana 8.5.14 to fix these issues.&lt;/p&gt;
&lt;p&gt;Release 9.2, latest release, also containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.2](https://grafana.com/grafana/download/9.2)&lt;/p&gt;
&lt;p&gt;Release 9.1.8, only containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.1.8](https://grafana.com/grafana/download/9.1.8)&lt;/p&gt;
&lt;p&gt;Release 8.5.14, only containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 8.5.14](https://grafana.com/grafana/download/8.5.14)&lt;/p&gt;
&lt;p&gt;Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure&amp;#39;s Grafana as a service offering.&lt;/p&gt;
&lt;p&gt;## Improper authentication - CVE-2022-39229&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;On September 7 as a result of an internal security audit we have discovered a security vulnerability in Grafana basic authentication, related to the usage of username and email address.&lt;/p&gt;
&lt;p&gt;In Grafana, a user’s username and email address are unique fields, that means no other user can have the same username or email address as another user.&lt;/p&gt;
&lt;p&gt;In addition, a user can have an email address as a username and Grafana…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gj7m-853r-289r</guid>
    </item>
    <item>
      <title>gsd-2022-39229</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39229</link>
      <description>gsd-2022-39229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39229</guid>
    </item>
    <item>
      <title>OESA-2024-2260 — grafana security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2260</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: grafana, openEuler:24.03-LTS: grafana, openEuler:22.03-LTS-SP4: grafana, openEuler:22.03-LTS-SP3: grafana, openEuler:20.03-LTS-SP4: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp; OpenTSDB.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;amp;apos;s login attempt by registering someone else&amp;amp;apos;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;amp;apos;s password won’t match with `user_2`&amp;amp;apos;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.(CVE-2022-39229)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: grafana, openEuler:24.03-LTS: grafana, openEuler:22.03-LTS-SP4: grafana, openEuler:22.03-LTS-SP3: grafana, openEuler:20.03-LTS-SP4: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp; OpenTSDB.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;amp;apos;s login attempt by registering someone else&amp;amp;apos;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;amp;apos;s password won’t match with `user_2`&amp;amp;apos;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.(CVE-2022-39229)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2260</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12508-1 — grafana-8.5.14-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12508-1</link>
      <description>&lt;p&gt;grafana-8.5.14-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grafana-8.5.14-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12508-1</guid>
    </item>
    <item>
      <title>RHSA-2023:3642 — Red Hat Security Advisory: Red Hat Ceph Storage 6.1 Container security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3642</link>
      <description>&lt;p&gt;ramda: prototype poisoning eventsource: Exposure of Sensitive Information golang: net/http: improper sanitization of Transfer-Encoding header golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters marked: regular expression block.def may lead Denial of Service marked: regular expression inline.reflinkSearch may lead Denial of Service grafana: Use of Cache Containing Sensitive Information golang: encoding/pem: fix stack overflow in Decode Moment.js: Path traversal  in moment.locale grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix golang: net/http: handle server errors after sending GOAWAY golang: encoding/xml: stack exhaustion in Decoder.Skip golang: crypto/elliptic: panic caused by oversized scalar golang: syscall: faccessat checks wrong group golang: crypto/tls: session tickets lack random ticket_age_add golang: io/fs: stack exhaustion in Glob golang: compress/gzip: stack exhaustion in Reader.Read golang: path/filepath: stack exhaustion in Glob golang: encoding/xml: stack exhaustion in Unmarshal golang: encoding/gob: stack exhaustion in Decoder.Decode grafana: stored XSS vulnerability grafana: OAuth account takeover grafana: plugin signature bypass grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: math/big: decoding big.Float and big.Rat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ramda: prototype poisoning eventsource: Exposure of Sensitive Information golang: net/http: improper sanitization of Transfer-Encoding header golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters marked: regular expression block.def may lead Denial of Service marked: regular expression inline.reflinkSearch may lead Denial of Service grafana: Use of Cache Containing Sensitive Information golang: encoding/pem: fix stack overflow in Decode Moment.js: Path traversal  in moment.locale grafana: An information leak issue was discovered in Grafana through 7.3.4, when integrated with Zabbix golang: net/http: handle server errors after sending GOAWAY golang: encoding/xml: stack exhaustion in Decoder.Skip golang: crypto/elliptic: panic caused by oversized scalar golang: syscall: faccessat checks wrong group golang: crypto/tls: session tickets lack random ticket_age_add golang: io/fs: stack exhaustion in Glob golang: compress/gzip: stack exhaustion in Reader.Read golang: path/filepath: stack exhaustion in Glob golang: encoding/xml: stack exhaustion in Unmarshal golang: encoding/gob: stack exhaustion in Decoder.Decode grafana: stored XSS vulnerability grafana: OAuth account takeover grafana: plugin signature bypass grafana: data source and plugin proxy endpoints leaking authentication tokens to some destination plugins golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working golang: math/big: decoding big.Float and big.Rat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3642</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0352-1 — Security update for SUSE Manager Client Tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0352-1</link>
      <description>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Client Tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0352-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-39229</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39229</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;#39;s login attempt by registering someone else&amp;#39;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;#39;s password won’t match with `user_2`&amp;#39;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user&amp;#39;s login attempt by registering someone else&amp;#39;e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user can have the same username or email address as another user. A user can have an email address as a username. However, the login system allows users to log in with either username or email address. Since Grafana allows a user to log in with either their username or email address, this creates an usual behavior where `user_1` can register with one email address and `user_2` can register their username as `user_1`’s email address. This prevents `user_1` logging into the application since `user_1`&amp;#39;s password won’t match with `user_2`&amp;#39;s email address. Versions 9.1.8 and 8.5.14 contain a patch. There are no workarounds for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39229</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1702 — Grafana: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1702</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1702</guid>
    </item>
  </channel>
</rss>
