The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grafana | Aug 22, 2024 | Mar 22, 2021 |
| Suse | — | Upgrade python2-mgr-osadUpgrade ansible-testUpgrade python3-suseregisterinfoUpgrade python2-mgr-cfg-actionsUpgrade python3-mgr-cfg-clientUpgrade mgr-pushUpgrade mgr-custom-infoUpgrade python2-suseregisterinfoUpgrade spacewalk-checkUpgrade grafanaUpgrade python2-mgr-osa-dispatcherUpgrade mgr-osadUpgrade python2-mgr-osa-commonUpgrade python2-rhnlibUpgrade python3-mgr-osa-dispatcherUpgrade mgr-cfg-clientUpgrade python3-spacewalk-koanUpgrade mgr-osa-dispatcherUpgrade mgr-cfg-managementUpgrade python2-spacewalk-client-toolsUpgrade mgr-cfgUpgrade golang-github-prometheus-prometheusUpgrade python3-mgr-cfg-managementUpgrade python3-mgr-virtualization-hostUpgrade python2-mgr-cfg-managementUpgrade python2-mgr-pushUpgrade python3-spacewalk-client-toolsUpgrade python2-mgr-virtualization-hostUpgrade python2-mgr-cfgUpgrade python3-mgr-osa-commonUpgrade ansibleUpgrade python2-spacewalk-checkUpgrade spacewalk-koanUpgrade python2-spacewalk-client-setupUpgrade python2-mgr-cfg-clientUpgrade spacecmdUpgrade python3-mgr-virtualization-commonUpgrade ansible-docUpgrade spacewalk-client-setupUpgrade python3-mgr-pushUpgrade python3-mgr-cfgUpgrade python2-mgr-virtualization-commonUpgrade python2-spacewalk-koanUpgrade python2-uyuni-common-libsUpgrade suseregisterinfoUpgrade spacewalk-oscapUpgrade python3-mgr-osadUpgrade python2-spacewalk-oscapUpgrade python3-rhnlibUpgrade mgr-virtualization-hostUpgrade dracut-saltbootUpgrade python3-spacewalk-checkUpgrade mgr-cfg-actionsUpgrade python3-spacewalk-oscapUpgrade python3-uyuni-common-libsUpgrade spacewalk-client-toolsUpgrade python3-mgr-cfg-actionsUpgrade python3-spacewalk-client-setup | Aug 13, 2021 | Mar 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub