{"id":"CVE-2022-39307","title":"grafana: User enumeration via forget password (CVE-2022-39307)","summary":"An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cvssSource":"vendor","cwe":"CWE-209","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["openshift_service_mesh 2.0","openshift_service_mesh 2.1","advanced_cluster_management_for_kubernetes 2","ceph_storage 3","ceph_storage 4","ceph_storage 5","enterprise_linux 8","openshift_container_platform 3.11","storage 3","ceph_storage_6_1_tools","enterprise_linux_appstream_v_9"],"patched":["ceph_storage_6_1_tools","enterprise_linux_appstream_v_9"],"published":"2022-11-08","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:43:49+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39307.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39307.json"},{"url":"https://access.redhat.com/security/cve/CVE-2022-39307"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2138015"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-39307"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39307"},{"url":"https://grafana.com/blog/2022/11/08/security-release-new-versions-of-grafana-with-critical-and-moderate-fixes-for-cve-2022-39328-cve-2022-39307-and-cve-2022-39306/"},{"url":"https://access.redhat.com/errata/RHSA-2023:3642"},{"url":"https://access.redhat.com/errata/RHSA-2023:6420"},{"url":"https://github.com/grafana/grafana/security/advisories/GHSA-3p62-42x7-gxg5"},{"url":"https://github.com/grafana/grafana"},{"url":"https://security.netapp.com/advisory/ntap-20221215-0004"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00748,"epssPercentile":0.53406,"aliases":["GHSA-3p62-42x7-gxg5","BIT-grafana-2022-39307","GO-2024-2844"],"ecosystem":"go","scores":{"vendor":5.3,"osv":6.7},"ingestedAt":"2026-09-12T03:13:01.749Z","slug":"CVE-2022-39307","body":"## Overview\n\nAn information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.\n\n## Vendor advisories\n\n- **RHSA-2023:3642** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2023-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:3642)\n- **RHSA-2023:6420** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6420)\n- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, Red Hat Ceph Storage 5, … · no fix planned: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Ceph Storage 3, Red Hat OpenShift Container Platform 3.11, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39307.json)\n\n**grafana: User enumeration via forget password** — rated Moderate by Red Hat. Released 2022-11-08, updated 2026-09-17.\n\nAffected:\n\n- OpenShift Service Mesh 2.0\n- OpenShift Service Mesh 2.1\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ceph Storage 3\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat Storage 3\n\nFixed:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Red Hat Enterprise Linux AppStream (v. 9)\n\nNo fix planned:\n\n- OpenShift Service Mesh 2.0\n- OpenShift Service Mesh 2.1\n- Red Hat Ceph Storage 3\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat Storage 3\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Enterprise Linux 8\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n\nNot affected:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Logging Subsystem for Red Hat OpenShift\n- OpenShift Service Mesh 2\n- Red Hat build of Quarkus\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift GitOps\n\n## Remediation\n\nFor details on how to apply this update, see Upgrade a Red Hat Ceph Storage\ncluster using cephadm in the Red Hat Storage Ceph Upgrade\nGuide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420\n\n## Package advisory (CVE-2022-39307)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 9.0.0, < 9.2.4`\n- `github.com/grafana/grafana < 8.5.15`\n\nPatched in:\n\n- `github.com/grafana/grafana 9.2.4`\n- `github.com/grafana/grafana 8.5.15`\n\nSource: https://osv.dev/vulnerability/GHSA-3p62-42x7-gxg5","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":206302,"id":"CVE-2022-39307","ts":1789663195977,"field":"cvss","old":"6.7","new":"5.3"}]}