Medium severity5.7NVD Advisory· Published Dec 20, 2022· Updated Jun 17, 2026
CVE-2022-44643
CVE-2022-44643
Description
A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using this policy with the affected versions of the software. This issue affects: Grafana Labs Grafana Enterprise Metrics GEM 1.X versions prior to 1.7.1 on AMD64; GEM 2.X versions prior to 2.3.1 on AMD64.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Grafana Labs/Grafana Enterprise Metricsdescription
- Range: <1.7.1, <2.3.1
Patches
Vulnerability mechanics
References
2- grafana.com/docs/enterprise-metrics/v2.4.x/downloads/nvdPatchRelease NotesVendor Advisory
- grafana.com/docs/enterprise-metrics/v2.4.x/downloads/nvdPatchRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.