{"id":"CVE-2022-32276","details":"Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability","aliases":["BIT-grafana-2022-32276"],"modified":"2026-08-12T03:51:18.023488594Z","published":"2022-06-17T11:38:27Z","database_specific":{"isDisputed":true,"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32276.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/BrotherOfJhonny/grafana/blob/main/README.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32276.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32276"},{"type":"REPORT","url":"https://github.com/grafana/grafana/issues/50336"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grafana/grafana","events":[{"introduced":"b7d2911caccbc79c63d2e585b95087824d945ede"},{"last_affected":"b7d2911caccbc79c63d2e585b95087824d945ede"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:grafana:grafana:8.4.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.4.3"},{"last_affected":"8.4.3"}]}}],"versions":["8.4.3","v8.4.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32276.json"}}],"schema_version":"1.9.0"}