cvedb.io
CVE-2022-28660
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2022-05-20T15:15:10.167 · Last modified 2026-06-17T04:38:48.247

Summary

The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

Affected products

grafana — grafana

Does this affect you?

Add your gear to cvedb and we'll alert you only when grafana ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.