Company
Date Published
Author
Emil Tullstedt
Word count
717
Language
English
Hacker News points
None

Summary

CVE-2022-32276 and CVE-2022-32275 were reported as potential vulnerabilities in Grafana, focusing on UI issues that Grafana Labs assessed as non-security impacting. Despite CVE-2022-32275 being assigned a severity score of 7.5 HIGH, Grafana Labs maintains that neither CVE poses a security threat, as both involve the display of the 'not found' page within the regular UI without granting privileged access. Grafana Labs is engaging with MITRE to reconsider the assigned severity score and encourages public discussion on the two open GitHub issues tracking these concerns. The company appreciates the report from the community and invites further security reports through their designated email, emphasizing the importance of confidentiality until a fix is deployed.