CVE-2024-1442

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
07/03/2024
Last modified:
11/03/2025

Description

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.<br /> Doing this will grant the user access to read, query, edit and delete all data sources within the organization.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* 8.5.0 (including) 9.5.7 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.12 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* 10.1.0 (including) 10.1.8 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* 10.2.0 (including) 10.2.5 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* 10.3.0 (including) 10.3.4 (excluding)