Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2022-31123
HistoryOct 13, 2022 - 10:15 p.m.

CVE-2022-31123

2022-10-1322:15:00
Alpine Linux Development Team
security.alpinelinux.org
19
grafana
observability
data visualization
vulnerability
plugin signature
verification
bypass
patch
workaround
untrusted sources
unix

EPSS

0.001

Percentile

32.7%

Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.

OSVersionArchitecturePackageVersionFilename
Alpine3.16-communitynoarchgrafana= 8.5.13-r1UNKNOWN