{"id":"CVE-2022-39324","title":"grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)","summary":"A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the \"Open original dashboard\" button.","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L","cvssSource":"vendor","cwe":"CWE-472","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","affected":["openshift_service_mesh 2.0","openshift_service_mesh 2.1","openshift_service_mesh 2","advanced_cluster_management_for_kubernetes 2","ceph_storage 3","ceph_storage 4","ceph_storage 5","enterprise_linux 8","openshift_container_platform 3.11","openshift_gitops","storage 3","ceph_storage_6_1_tools","enterprise_linux_appstream_v_9"],"patched":["ceph_storage_6_1_tools","enterprise_linux_appstream_v_9"],"published":"2023-01-30","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:35:47+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39324.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39324.json"},{"url":"https://access.redhat.com/security/cve/CVE-2022-39324"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2148252"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-39324"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39324"},{"url":"https://grafana.com/blog/2023/01/25/grafana-security-releases-new-versions-with-fixes-for-cve-2022-23552-cve-2022-41912-and-cve-2022-39324/"},{"url":"https://access.redhat.com/errata/RHSA-2023:3642"},{"url":"https://access.redhat.com/errata/RHSA-2023:6420"},{"url":"https://github.com/grafana/grafana/security/advisories/GHSA-4724-7jwc-3fpw"},{"url":"https://github.com/grafana/grafana/pull/60232"},{"url":"https://github.com/grafana/grafana/pull/60256"},{"url":"https://github.com/grafana/grafana/commit/239888f22983010576bb3a9135a7294e88c0c74a"},{"url":"https://github.com/grafana/grafana/commit/d7dcea71ea763780dc286792a0afd560bff2985c"},{"url":"https://github.com/grafana/grafana"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00828,"epssPercentile":0.55953,"aliases":["GHSA-4724-7jwc-3fpw","BIT-grafana-2022-39324","GO-2024-2867"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.751Z","slug":"CVE-2022-39324","body":"## Overview\n\nA flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the \"Open original dashboard\" button.\n\n## Vendor advisories\n\n- **RHSA-2023:3642** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2023-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:3642)\n- **RHSA-2023:6420** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6420)\n- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, OpenShift Service Mesh 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, … · no fix planned: OpenShift Service Mesh 2.0, Red Hat Ceph Storage 3, Red Hat OpenShift Container Platform 3.11, Red Hat Storage 3, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39324.json)\n\n**grafana: Spoofing of the originalUrl parameter of snapshots** — rated Moderate by Red Hat. Released 2022-01-01, updated 2026-09-17.\n\nAffected:\n\n- OpenShift Service Mesh 2.0\n- OpenShift Service Mesh 2.1\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ceph Storage 3\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat OpenShift GitOps\n- Red Hat Storage 3\n\nFixed:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Red Hat Enterprise Linux AppStream (v. 9)\n\nNo fix planned:\n\n- OpenShift Service Mesh 2.0\n- Red Hat Ceph Storage 3\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat Storage 3\n- OpenShift Service Mesh 2.1\n- OpenShift Service Mesh 2\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift GitOps\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n\nNot affected:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Logging Subsystem for Red Hat OpenShift\n- Red Hat build of Quarkus\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFor details on how to apply this update, see Upgrade a Red Hat Ceph Storage\ncluster using cephadm in the Red Hat Storage Ceph Upgrade\nGuide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420\n\n## Package advisory (CVE-2022-39324)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 9.0.0, < 9.2.8`\n- `github.com/grafana/grafana < 8.5.16`\n\nPatched in:\n\n- `github.com/grafana/grafana 9.2.8`\n- `github.com/grafana/grafana 8.5.16`\n\nSource: https://osv.dev/vulnerability/GHSA-4724-7jwc-3fpw","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}