CVE-2021-27962

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2021
Last modified:
12/07/2022

Description

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 7.2.0 (including) 7.3.10 (excluding)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:* 7.4.0 (including) 7.4.5 (excluding)