The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grafana | Aug 22, 2024 | Mar 22, 2021 |
| Suse | — | Upgrade python3-mgr-osa-dispatcherUpgrade python2-mgr-osadUpgrade python3-mgr-virtualization-commonUpgrade mgr-pushUpgrade python2-mgr-osa-dispatcherUpgrade python2-mgr-virtualization-hostUpgrade python3-mgr-cfg-actionsUpgrade python2-suseregisterinfoUpgrade python3-rhnlibUpgrade python3-spacewalk-koanUpgrade golang-github-prometheus-prometheusUpgrade ansibleUpgrade mgr-cfg-managementUpgrade python3-spacewalk-checkUpgrade python3-mgr-pushUpgrade python3-suseregisterinfoUpgrade python3-spacewalk-oscapUpgrade python2-rhnlibUpgrade python2-mgr-cfg-managementUpgrade spacewalk-oscapUpgrade python2-mgr-cfgUpgrade spacewalk-koanUpgrade ansible-docUpgrade mgr-osadUpgrade mgr-cfgUpgrade mgr-osa-dispatcherUpgrade python3-mgr-cfgUpgrade python2-spacewalk-client-toolsUpgrade python2-mgr-pushUpgrade python2-mgr-osa-commonUpgrade python3-uyuni-common-libsUpgrade python3-spacewalk-client-setupUpgrade python2-mgr-cfg-actionsUpgrade python2-mgr-virtualization-commonUpgrade spacewalk-client-toolsUpgrade mgr-virtualization-hostUpgrade dracut-saltbootUpgrade python3-mgr-osadUpgrade python3-mgr-virtualization-hostUpgrade python3-mgr-cfg-clientUpgrade spacewalk-client-setupUpgrade python3-mgr-cfg-managementUpgrade python2-spacewalk-oscapUpgrade python3-spacewalk-client-toolsUpgrade spacecmdUpgrade python3-mgr-osa-commonUpgrade python2-spacewalk-checkUpgrade mgr-cfg-actionsUpgrade python2-spacewalk-client-setupUpgrade ansible-testUpgrade grafanaUpgrade python2-uyuni-common-libsUpgrade python2-spacewalk-koanUpgrade suseregisterinfoUpgrade spacewalk-checkUpgrade mgr-custom-infoUpgrade mgr-cfg-clientUpgrade python2-mgr-cfg-client | Aug 13, 2021 | Mar 22, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub