Improper access control in Grafana - CVE-2024-1442
Published: March 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can use Grafana API to create a data source with UID set to *, and gain access to read, query, edit and delete all data sources within the organization.
Affected software
Communications Unified Assurance
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Advanced Cluster Management for Kubernetes
Storage Ceph
How to mitigate CVE-2024-1442
Red Hat Advanced Cluster Management for Kubernetes - update to 2.12.0
Storage Ceph - update to 7.1