CVE-2024-1442
07.03.2024, 18:15
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.Enginsight
Vendor | Product | Version |
---|---|---|
grafana | grafana | 8.5.0 ≤ 𝑥 < 9.5.7 |
grafana | grafana | 10.0.0 ≤ 𝑥 < 10.0.12 |
grafana | grafana | 10.1.0 ≤ 𝑥 < 10.1.8 |
grafana | grafana | 10.2.0 ≤ 𝑥 < 10.2.5 |
grafana | grafana | 10.3.0 ≤ 𝑥 < 10.3.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration