---
id: CVE-2022-39307
title: 'grafana: User enumeration via forget password (CVE-2022-39307)'
summary: >-
  An information leak was discovered in Grafana. Remote unauthenticated users
  could exploit the forget password feature to discover which user accounts
  exist.
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: vendor
cwe: CWE-209
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - openshift_service_mesh 2.0
  - openshift_service_mesh 2.1
  - advanced_cluster_management_for_kubernetes 2
  - ceph_storage 3
  - ceph_storage 4
  - ceph_storage 5
  - enterprise_linux 8
  - openshift_container_platform 3.11
  - storage 3
  - ceph_storage_6_1_tools
  - enterprise_linux_appstream_v_9
patched:
  - ceph_storage_6_1_tools
  - enterprise_linux_appstream_v_9
published: '2022-11-08'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:43:49+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39307.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39307.json
  - url: 'https://access.redhat.com/security/cve/CVE-2022-39307'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2138015'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2022-39307'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-39307'
  - url: >-
      https://grafana.com/blog/2022/11/08/security-release-new-versions-of-grafana-with-critical-and-moderate-fixes-for-cve-2022-39328-cve-2022-39307-and-cve-2022-39306/
  - url: 'https://access.redhat.com/errata/RHSA-2023:3642'
  - url: 'https://access.redhat.com/errata/RHSA-2023:6420'
  - url: 'https://github.com/grafana/grafana/security/advisories/GHSA-3p62-42x7-gxg5'
  - url: 'https://github.com/grafana/grafana'
  - url: 'https://security.netapp.com/advisory/ntap-20221215-0004'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00748
epssPercentile: 0.53442
aliases:
  - GHSA-3p62-42x7-gxg5
  - BIT-grafana-2022-39307
  - GO-2024-2844
ecosystem: go
scores:
  vendor: 5.3
  osv: 6.7
ingestedAt: '2026-09-12T03:13:01.749Z'
---

## Overview

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

## Vendor advisories

- **RHSA-2023:3642** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2023-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:3642)
- **RHSA-2023:6420** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6420)
- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, Red Hat Ceph Storage 5, … · no fix planned: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, Red Hat Ceph Storage 3, Red Hat OpenShift Container Platform 3.11, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39307.json)

**grafana: User enumeration via forget password** — rated Moderate by Red Hat. Released 2022-11-08, updated 2026-09-17.

Affected:

- OpenShift Service Mesh 2.0
- OpenShift Service Mesh 2.1
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 3
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 3.11
- Red Hat Storage 3

Fixed:

- Red Hat Ceph Storage 6.1 Tools
- Red Hat Enterprise Linux AppStream (v. 9)

No fix planned:

- OpenShift Service Mesh 2.0
- OpenShift Service Mesh 2.1
- Red Hat Ceph Storage 3
- Red Hat OpenShift Container Platform 3.11
- Red Hat Storage 3
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Enterprise Linux 8
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5

Not affected:

- Red Hat Ceph Storage 6.1 Tools
- Logging Subsystem for Red Hat OpenShift
- OpenShift Service Mesh 2
- Red Hat build of Quarkus
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift GitOps

## Remediation

For details on how to apply this update, see Upgrade a Red Hat Ceph Storage
cluster using cephadm in the Red Hat Storage Ceph Upgrade
Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420

## Package advisory (CVE-2022-39307)

Affected packages:

- `github.com/grafana/grafana >= 9.0.0, < 9.2.4`
- `github.com/grafana/grafana < 8.5.15`

Patched in:

- `github.com/grafana/grafana 9.2.4`
- `github.com/grafana/grafana 8.5.15`

Source: https://osv.dev/vulnerability/GHSA-3p62-42x7-gxg5
