Privilege Escalation in Data Sources in Grafana

Medium
Advisory ID:
CVE-2024-1442
Published:
2024-03-07
Product:
Grafana
CVSS Score:
6.0
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Fixed Versions:
>=9.5.7
>=10.0.12
>=10.1.8
>=10.2.5
>=10.3.4

Summary

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

Impacted Versions:

  • 8.5.0 < 9.5.7
  • 10.0.0 < 10.0.12
  • 10.1.0 < 10.1.8
  • 10.2.0 < 10.2.5
  • 10.3.0 < 10.3.4
CVE-2024-1442: Privilege Escalation in Data Sources in Grafana | Grafana Labs