---
id: CVE-2022-39324
title: 'grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)'
summary: >-
  A flaw was found in the grafana package. While creating a snapshot, an
  attacker may manipulate a hidden HTTP parameter to inject a malicious URL in
  the "Open original dashboard" button.
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L'
cvssSource: vendor
cwe: CWE-472
vendor: Red Hat
product: Red Hat Enterprise Linux 8
affected:
  - openshift_service_mesh 2.0
  - openshift_service_mesh 2.1
  - openshift_service_mesh 2
  - advanced_cluster_management_for_kubernetes 2
  - ceph_storage 3
  - ceph_storage 4
  - ceph_storage 5
  - enterprise_linux 8
  - openshift_container_platform 3.11
  - openshift_gitops
  - storage 3
  - ceph_storage_6_1_tools
  - enterprise_linux_appstream_v_9
patched:
  - ceph_storage_6_1_tools
  - enterprise_linux_appstream_v_9
published: '2023-01-30'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:35:47+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39324.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39324.json
  - url: 'https://access.redhat.com/security/cve/CVE-2022-39324'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2148252'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2022-39324'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-39324'
  - url: >-
      https://grafana.com/blog/2023/01/25/grafana-security-releases-new-versions-with-fixes-for-cve-2022-23552-cve-2022-41912-and-cve-2022-39324/
  - url: 'https://access.redhat.com/errata/RHSA-2023:3642'
  - url: 'https://access.redhat.com/errata/RHSA-2023:6420'
  - url: 'https://github.com/grafana/grafana/security/advisories/GHSA-4724-7jwc-3fpw'
  - url: 'https://github.com/grafana/grafana/pull/60232'
  - url: 'https://github.com/grafana/grafana/pull/60256'
  - url: >-
      https://github.com/grafana/grafana/commit/239888f22983010576bb3a9135a7294e88c0c74a
  - url: >-
      https://github.com/grafana/grafana/commit/d7dcea71ea763780dc286792a0afd560bff2985c
  - url: 'https://github.com/grafana/grafana'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00828
epssPercentile: 0.55633
aliases:
  - GHSA-4724-7jwc-3fpw
  - BIT-grafana-2022-39324
  - GO-2024-2867
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.751Z'
---

## Overview

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

## Vendor advisories

- **RHSA-2023:3642** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2023-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2023:3642)
- **RHSA-2023:6420** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2023-11-07 · [advisory](https://access.redhat.com/errata/RHSA-2023:6420)
- **Red Hat VEX** · Moderate · affected: OpenShift Service Mesh 2.0, OpenShift Service Mesh 2.1, OpenShift Service Mesh 2, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 3, Red Hat Ceph Storage 4, … · no fix planned: OpenShift Service Mesh 2.0, Red Hat Ceph Storage 3, Red Hat OpenShift Container Platform 3.11, Red Hat Storage 3, … · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2022/cve-2022-39324.json)

**grafana: Spoofing of the originalUrl parameter of snapshots** — rated Moderate by Red Hat. Released 2022-01-01, updated 2026-09-17.

Affected:

- OpenShift Service Mesh 2.0
- OpenShift Service Mesh 2.1
- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 3
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 3.11
- Red Hat OpenShift GitOps
- Red Hat Storage 3

Fixed:

- Red Hat Ceph Storage 6.1 Tools
- Red Hat Enterprise Linux AppStream (v. 9)

No fix planned:

- OpenShift Service Mesh 2.0
- Red Hat Ceph Storage 3
- Red Hat OpenShift Container Platform 3.11
- Red Hat Storage 3
- OpenShift Service Mesh 2.1
- OpenShift Service Mesh 2
- Red Hat Enterprise Linux 8
- Red Hat OpenShift GitOps
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5

Not affected:

- Red Hat Ceph Storage 6.1 Tools
- Logging Subsystem for Red Hat OpenShift
- Red Hat build of Quarkus
- Red Hat OpenShift Container Platform 4

## Remediation

For details on how to apply this update, see Upgrade a Red Hat Ceph Storage
cluster using cephadm in the Red Hat Storage Ceph Upgrade
Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) https://access.redhat.com/errata/RHSA-2023:3642
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2023:6420

## Package advisory (CVE-2022-39324)

Affected packages:

- `github.com/grafana/grafana >= 9.0.0, < 9.2.8`
- `github.com/grafana/grafana < 8.5.16`

Patched in:

- `github.com/grafana/grafana 9.2.8`
- `github.com/grafana/grafana 8.5.16`

Source: https://osv.dev/vulnerability/GHSA-4724-7jwc-3fpw
