HomeGrafanaCVE-2022-44643

CVE-2022-44643

MEDIUM
5.7CVSS
Published: 2022-12-20
Updated: 2025-04-15
AI Analysis

Description

A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Grafana Labs Grafana Enterprise Metrics GEM 1.X versions prior to 1.7.1 on AMD64; GEM 2.X versions prior to 2.3.1 on AMD64.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
none
Availability
none
Weaknesses
NVD-CWE-OtherCWE-284

Metadata

Primary Vendor
GRAFANA
Published
12/20/2022
Last Modified
4/15/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

grafana : enterprise_metricsgrafana : enterprise_metrics

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-44643 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com