<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:49:30 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02627</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02627</link>
      <description>bdu:2024-02627</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02627</guid>
    </item>
    <item>
      <title>BIT-grafana-2022-39328 — Grafana vulnerable to race condition allowing privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/bit-grafana-2022-39328</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-grafana-2022-39328</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1006 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer une atteinte…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1006</link>
      <description>certfr-2022-avi-1006</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1006</guid>
    </item>
    <item>
      <title>cnvd-2022-78211</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-78211</link>
      <description>cnvd-2022-78211</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-78211</guid>
    </item>
    <item>
      <title>EUVD-2026-266775</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266775</link>
      <description>EUVD-2026-266775</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266775</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39328</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39328</link>
      <description>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39328</guid>
    </item>
    <item>
      <title>GHSA-vqc4-mpj8-jxch — Grafana Race condition allowing privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vqc4-mpj8-jxch</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes critical security fixes for CVE-2022-39328.&lt;/p&gt;
&lt;p&gt;Release 9.2.4, latest patch, also containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.2.4](https://grafana.com/grafana/download/9.2.4)&lt;/p&gt;
&lt;p&gt;Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering.&lt;/p&gt;
&lt;p&gt;## Privilege escalation&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Internal security audit identified a race condition in the Grafana codebase, which allowed an unauthenticated user to query an arbitrary endpoint in Grafana.
A race condition in the [HTTP context creation](https://github.com/grafana/grafana/blob/main/pkg/web/router.go#L153) could make a HTTP request being assigned the authentication/authorization middlewares of another call. Under heavy load it is possible that a call protected by a privileged middleware receives instead the middleware of a public query. 
As a result, an unauthenticated user can successfully query protected endpoints.&lt;/p&gt;
&lt;p&gt;The CVSS score for this vulnerability is [9.8 Critical](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;amp;version=3.1)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Unauthenticated…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/grafana/grafana&lt;/p&gt;
&lt;p&gt;Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes critical security fixes for CVE-2022-39328.&lt;/p&gt;
&lt;p&gt;Release 9.2.4, latest patch, also containing security fix:&lt;/p&gt;
&lt;p&gt;- [Download Grafana 9.2.4](https://grafana.com/grafana/download/9.2.4)&lt;/p&gt;
&lt;p&gt;Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering.&lt;/p&gt;
&lt;p&gt;## Privilege escalation&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Internal security audit identified a race condition in the Grafana codebase, which allowed an unauthenticated user to query an arbitrary endpoint in Grafana.
A race condition in the [HTTP context creation](https://github.com/grafana/grafana/blob/main/pkg/web/router.go#L153) could make a HTTP request being assigned the authentication/authorization middlewares of another call. Under heavy load it is possible that a call protected by a privileged middleware receives instead the middleware of a public query. 
As a result, an unauthenticated user can successfully query protected endpoints.&lt;/p&gt;
&lt;p&gt;The CVSS score for this vulnerability is [9.8 Critical](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;amp;version=3.1)&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Unauthenticated…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vqc4-mpj8-jxch</guid>
    </item>
    <item>
      <title>gsd-2022-39328</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39328</link>
      <description>gsd-2022-39328</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39328</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-39328</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39328</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: grafana&lt;/p&gt;
&lt;p&gt;Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39328</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0334 — Grafana: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0334</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Benutzerrechte zu erlangen, seine Privilegien zu erweitern und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Benutzerrechte zu erlangen, seine Privilegien zu erweitern und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0334</guid>
    </item>
  </channel>
</rss>
