{"id":"CVE-2022-39306","title":"grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)","summary":"An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup lin…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cvssSource":"vendor","cwe":"CWE-303","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["openshift_service_mesh 2.0","openshift_service_mesh 2.1","ceph_storage 3","ceph_storage 4","ceph_storage 5","enterprise_linux 8","openshift_container_platform 3.11","storage 3","ceph_storage_6_1_tools","enterprise_linux_appstream_v_9"],"patched":["ceph_storage_6_1_tools","enterprise_linux_appstream_v_9"],"published":"2022-11-08","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:43:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39306.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39306.json"},{"url":"https://access.redhat.com/security/cve/CVE-2022-39306"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2138014"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-39306"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39306"},{"url":"https://grafana.com/blog/2022/11/08/security-release-new-versions-of-grafana-with-critical-and-moderate-fixes-for-cve-2022-39328-cve-2022-39307-and-cve-2022-39306/"},{"url":"https://access.redhat.com/errata/RHSA-2023:3642"},{"url":"https://access.redhat.com/errata/RHSA-2023:6420"},{"url":"https://github.com/grafana/grafana/security/advisories/GHSA-2x6g-h2hg-rq84"},{"url":"https://github.com/grafana/grafana"},{"url":"https://security.netapp.com/advisory/ntap-20221215-0004"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.0076,"epssPercentile":0.53336,"aliases":["GHSA-2x6g-h2hg-rq84","BIT-grafana-2022-39306","GO-2024-2843"],"ecosystem":"go","scores":{"vendor":8.1,"osv":6.4},"ingestedAt":"2026-09-12T03:13:01.747Z","slug":"CVE-2022-39306","body":"## Overview\n\nAn authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup link. The highest impacts to the system are confidentiality and integrity.\n\n## Vendor advisories\n\n- **RHSA-2023:3642** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2023-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:3642)\n- **RHSA-2023:6420** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6420)\n- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, Red Hat Ceph Storage 5, Red Hat Enterprise Linux 8, … · no fix planned: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Ceph Storage 3, Red Hat OpenShift Container Platform 3.11, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39306.json)\n\n**grafana: email addresses and usernames cannot be trusted** — rated Moderate by Red Hat. Released 2022-11-08, updated 2026-09-17.\n\nAffected:\n\n- OpenShift Service Mesh 2.0\n- OpenShift Service Mesh 2.1\n- Red Hat Ceph Storage 3\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat Storage 3\n\nFixed:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Red Hat Enterprise Linux AppStream (v. 9)\n\nNo fix planned:\n\n- OpenShift Service Mesh 2.0\n- OpenShift Service Mesh 2.1\n- Red Hat Ceph Storage 3\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat Storage 3\n- Red Hat Enterprise Linux 8\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n\nNot affected:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Logging Subsystem for Red Hat OpenShift\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat build of Quarkus\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n\n## Remediation\n\nFor details on how to apply this update, see Upgrade a Red Hat Ceph Storage\ncluster using cephadm in the Red Hat Storage Ceph Upgrade\nGuide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420\n\n## Package advisory (CVE-2022-39306)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 8.0.0, < 8.5.15`\n- `github.com/grafana/grafana >= 9.0.0, < 9.2.4`\n\nPatched in:\n\n- `github.com/grafana/grafana 8.5.15`\n- `github.com/grafana/grafana 9.2.4`\n\nSource: https://osv.dev/vulnerability/GHSA-2x6g-h2hg-rq84","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":206304,"id":"CVE-2022-39306","ts":1789663196159,"field":"cvss","old":"6.4","new":"8.1"},{"seq":206303,"id":"CVE-2022-39306","ts":1789663196159,"field":"severity","old":"medium","new":"high"}]}