Privilege Escalation in Data Sources in Grafana
Medium
- Advisory ID:
- CVE-2024-1442
- Published:
- 2024-03-07
- Product:
- Grafana
- CVSS Score:
- 6.0
- CVSS Vector:
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
- Fixed Versions:
- >=9.5.7>=10.0.12>=10.1.8>=10.2.5>=10.3.4
Summary
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Impacted Versions:
- 8.5.0 < 9.5.7
- 10.0.0 < 10.0.12
- 10.1.0 < 10.1.8
- 10.2.0 < 10.2.5
- 10.3.0 < 10.3.4