Vulnerability CVE-2022-44643


Published: 2022-12-20

Description:
In Grafana Enterprise Metrics (GEM) before 1.7.1 and 2.x before 2.3.1, after creating an Access Policy that is granted access to all tenants as well as specified a specific label matcher, the label matcher is erroneously not propagated to queries performed with this access policy. Thus, more access is granted to the policy than intended.

 References:
https://grafana.com/products/enterprise/metrics/
https://grafana.com/docs/enterprise-metrics/v2.4.x/downloads/#v171----november-14th-2022
https://grafana.com/docs/enterprise-metrics/v2.4.x/downloads/#v231----november-14th-2022

Copyright 2026, cxsecurity.com

 

Back to Top