In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
CVSS Details
- CVSS 4.0 Base Score: 5.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-grafana | Oct 10, 2024 | Sep 26, 2024 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 26, 2024 |
| Suse | — | suse-upgrade-dracut-saltbootsuse-upgrade-golang-github-prometheus-promususe-upgrade-grafanasuse-upgrade-spacecmdsuse-upgrade-supportutils-plugin-saltsuse-upgrade-supportutils-plugin-susemanager-client | Dec 5, 2025 | Feb 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub