Bugzilla – Bug 1221174
VUL-0: CVE-2024-1442: grafana: Improper priviledge managent for users with data source permissions
Last modified: 2024-03-08 12:11:28 UTC
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-1442 https://www.cve.org/CVERecord?id=CVE-2024-1442 https://grafana.com/security/security-advisories/cve-2024-1442/ https://grafana.com/blog/2024/03/07/grafana-security-release-medium-severity-security-fix-for-cve-2024-1442/ https://bugzilla.redhat.com/show_bug.cgi?id=2268486
Closing since it affects only Grafana Cloud and Grafana Enterprise [0], so no shipped products are affected. [0] https://grafana.com/blog/2024/03/07/grafana-security-release-medium-severity-security-fix-for-cve-2024-1442/