CVE-2022-39324Medium· 6.7▾ SunlitA flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.8%
Last analysed / modified upstream
A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.
grafana: Spoofing of the originalUrl parameter of snapshots — rated Moderate by Red Hat. Released 2022-01-01, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420
Affected packages:
github.com/grafana/grafana >= 9.0.0, < 9.2.8github.com/grafana/grafana < 8.5.16Patched in:
github.com/grafana/grafana 9.2.8github.com/grafana/grafana 8.5.16Connected by shared product, vendor, weakness, or advisory.
CVE-2022-39307Medium· 5.3grafana: User enumeration via forget password (CVE-2022-39307)
CVE-2022-39306High· 8.1grafana: email addresses and usernames cannot be trusted (CVE-2022-39306)
CVE-2026-39825Medium· 6.5net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2…
CVE-2026-42308Medium· 6.2Pillow: Pillow: Denial of Service via integer overflow in font processing (CVE-2026-42308)
CVE-2026-73646High· 7.5PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree
CVE-2026-89665High· 7.0kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE (CVE-2026-89665)