#VU87328 Improper access control in Grafana - CVE-2024-1442
Published: March 11, 2024
Grafana
Grafana Labs
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can use Grafana API to create a data source with UID set to *, and gain access to read, query, edit and delete all data sources within the organization.