BIT-grafana-image-renderer-2022-31176

    Dashboard / Vulnerabilities / BIT-grafana-image-renderer-2022-31176

    BIT-grafana-image-renderer-2022-31176

    Published: 6 Mar 2024Last Modified: 8 Sept 2026

    Summary: Grafana Image Renderer leaking files

    Details: Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana). All Grafana installations should be upgraded to version 3.6.1 as soon as possible. As a workaround it is possible to [disable HTTP remote rendering](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#plugingrafana-image-renderer).

    Affected packages

    Package

    Name: grafana-image-renderer

    Purl: pkg:bitnami/grafana-image-renderer

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.6.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-grafana-image-renderer-2022-31176 | CVE-DB