CVE-2024-8118
EUVD-2024-4894826.09.2024, 19:15
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| grafana | grafana | 8.5.0 ≤ 𝑥 < 10.3.10 | CNA |
| grafana | grafana | 10.4.0 ≤ 𝑥 < 10.4.9 | CNA |
| grafana | grafana | 11.0.0 ≤ 𝑥 < 11.0.5 | CNA |
| grafana | grafana | 11.1.0 ≤ 𝑥 < 11.1.6 | CNA |
| grafana | grafana | 11.2.0 ≤ 𝑥 < 11.2.1 | CNA |
Ubuntu Releases
Common Weakness Enumeration