CVE-2022-39307Medium· 5.3▾ SunlitAn information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.7%
Last analysed / modified upstream
6.7 → 5.3
An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.
grafana: User enumeration via forget password — rated Moderate by Red Hat. Released 2022-11-08, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420
Affected packages:
github.com/grafana/grafana >= 9.0.0, < 9.2.4github.com/grafana/grafana < 8.5.15Patched in:
github.com/grafana/grafana 9.2.4github.com/grafana/grafana 8.5.15Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-39324Medium· 6.7grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)
CVE-2022-39306High· 8.1grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
CVE-2026-42308Medium· 6.2Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)
CVE-2026-69247Medium· 5.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-73646High· 7.5PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree
CVE-2026-89665High· 7.0kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (CVE-2026-89665)