Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-44643


A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Grafana Labs Grafana Enterprise Metrics GEM 1.X versions prior to 1.7.1 on AMD64; GEM 2.X versions prior to 2.3.1 on AMD64.


Published

2022-12-20T15:15:11.780

Last Modified

2025-04-15T20:15:37.970

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.7 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-Other
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application grafana enterprise_metrics < 1.7.1 Yes
Application grafana enterprise_metrics < 2.3.1 Yes
Hardware amd amd64 - No

References