---
id: CVE-2022-39306
title: 'grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)'
summary: >-
  An authentication bypass flaw was discovered in Grafana. This issue could
  allow a remote unauthenticated attacker to create an account and provide
  access to a certain organization, which can be exploited by gaining access to
  the signup lin…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-303
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - openshift_service_mesh 2.0
  - openshift_service_mesh 2.1
  - ceph_storage 3
  - ceph_storage 4
  - ceph_storage 5
  - enterprise_linux 8
  - openshift_container_platform 3.11
  - storage 3
  - ceph_storage_6_1_tools
  - enterprise_linux_appstream_v_9
patched:
  - ceph_storage_6_1_tools
  - enterprise_linux_appstream_v_9
published: '2022-11-08'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:43:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39306.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39306.json
  - url: 'https://access.redhat.com/security/cve/CVE-2022-39306'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2138014'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2022-39306'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-39306'
  - url: >-
      https://grafana.com/blog/2022/11/08/security-release-new-versions-of-grafana-with-critical-and-moderate-fixes-for-cve-2022-39328-cve-2022-39307-and-cve-2022-39306/
  - url: 'https://access.redhat.com/errata/RHSA-2023:3642'
  - url: 'https://access.redhat.com/errata/RHSA-2023:6420'
  - url: 'https://github.com/grafana/grafana/security/advisories/GHSA-2x6g-h2hg-rq84'
  - url: 'https://github.com/grafana/grafana'
  - url: 'https://security.netapp.com/advisory/ntap-20221215-0004'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0076
epssPercentile: 0.53827
aliases:
  - GHSA-2x6g-h2hg-rq84
  - BIT-grafana-2022-39306
  - GO-2024-2843
ecosystem: go
scores:
  vendor: 8.1
  osv: 6.4
ingestedAt: '2026-09-12T03:13:01.747Z'
---

## Overview

An authentication bypass flaw was discovered in Grafana. This issue could allow a remote unauthenticated attacker to create an account and provide access to a certain organization, which can be exploited by gaining access to the signup link. The highest impacts to the system are confidentiality and integrity.

## Vendor advisories

- **RHSA-2023:3642** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2023-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:3642)
- **RHSA-2023:6420** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6420)
- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, Red Hat Ceph Storage 5, Red Hat Enterprise Linux 8, … · no fix planned: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Ceph Storage 3, Red Hat OpenShift Container Platform 3.11, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39306.json)

**grafana: email addresses and usernames cannot be trusted** — rated Moderate by Red Hat. Released 2022-11-08, updated 2026-09-17.

Affected:

- OpenShift Service Mesh 2.0
- OpenShift Service Mesh 2.1
- Red Hat Ceph Storage 3
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 3.11
- Red Hat Storage 3

Fixed:

- Red Hat Ceph Storage 6.1 Tools
- Red Hat Enterprise Linux AppStream (v. 9)

No fix planned:

- OpenShift Service Mesh 2.0
- OpenShift Service Mesh 2.1
- Red Hat Ceph Storage 3
- Red Hat OpenShift Container Platform 3.11
- Red Hat Storage 3
- Red Hat Enterprise Linux 8
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5

Not affected:

- Red Hat Ceph Storage 6.1 Tools
- Logging Subsystem for Red Hat OpenShift
- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat build of Quarkus
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps

## Remediation

For details on how to apply this update, see Upgrade a Red Hat Ceph Storage
cluster using cephadm in the Red Hat Storage Ceph Upgrade
Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420

## Package advisory (CVE-2022-39306)

Affected packages:

- `github.com/grafana/grafana >= 8.0.0, < 8.5.15`
- `github.com/grafana/grafana >= 9.0.0, < 9.2.4`

Patched in:

- `github.com/grafana/grafana 8.5.15`
- `github.com/grafana/grafana 9.2.4`

Source: https://osv.dev/vulnerability/GHSA-2x6g-h2hg-rq84
