User with permissions to create a data source can CRUD all data sources

Medium
Advisory ID:CVE-2024-1442
Published:2024-03-07
Product:Grafana
CVSS Score:6.0
CVSS Vector:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Fixed Versions:
>=9.5.7
>=10.0.12
>=10.1.8
>=10.2.5
>=10.3.4

Summary

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

Impacted Versions:

  • 8.5.0 < 9.5.7
  • 10.0.0 < 10.0.12
  • 10.1.0 < 10.1.8
  • 10.2.0 < 10.2.5
  • 10.3.0 < 10.3.4