CVE-2024-8118

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
26/09/2024
Last modified:
15/04/2026

Description

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

References to Advisories, Solutions, and Tools