CVE-2024-6322

EUVD-2024-2596
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GRAFANACNA
5.4 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
grafanagrafana
11.1.0 ≤
𝑥
< 11.1.1
CNA
grafanagrafana
11.1.2 ≤
𝑥
< 11.1.3
CNA
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grafana
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
xenial
needs-triage