User with permissions to create a data source can CRUD all data sources
Advisory ID: | CVE-2024-1442 |
Published: | 2024-03-07 |
Product: | Grafana |
CVSS Score: | 6.0 |
CVSS Vector: | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L |
Fixed Versions: | >=9.5.7 >=10.0.12 >=10.1.8 >=10.2.5 >=10.3.4 |
Summary
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Impacted Versions:
- 8.5.0 < 9.5.7
- 10.0.0 < 10.0.12
- 10.1.0 < 10.1.8
- 10.2.0 < 10.2.5
- 10.3.0 < 10.3.4