CVE-2021-28146
Summary
| CVE | CVE-2021-28146 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-03-22 14:15:00 UTC |
| Updated | 2021-03-26 17:17:00 UTC |
| Description | The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release notes for Grafana 7.4.5 | Grafana Labs | MISC | grafana.com | |
| Grafana 6.7.6, 7.3.10, and 7.4.5 released with important security fixes for Grafana Enterprise | Grafana Labs | CONFIRM | grafana.com | |
| Grafana Enterprise | Grafana Labs | MISC | grafana.com | |
| oss-security - Grafana 7.4.5, 7.3.10 and 6.7.6 released with security fixes for Grafana Enterprose | CONFIRM | www.openwall.com | |
| Release notes for Grafana 7.3.10 | Grafana Labs | MISC | grafana.com | |
| Release Notes v6.7.x - Releases - Grafana Community | MISC | community.grafana.com | |
| Grafana Enterprise 6.7.6, 7.3.10 and 7.4.5 Security Update - Security Announcements - Grafana Labs Community Forums | MISC | community.grafana.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501864 Alpine Linux Security Update for grafana
- 730073 Grafana Enterprise Multiple Security Vulnerabilities
- 750959 OpenSUSE Security Update for SUSE Manager Client Tools (openSUSE-SU-2021:2675-1)
- 750960 OpenSUSE Security Update for grafana (openSUSE-SU-2021:2662-1)
- 750964 OpenSUSE Security Update for grafana (openSUSE-SU-2021:1148-1)
- 750980 OpenSUSE Security Update for SUSE Manager Client Tools (openSUSE-SU-2021:1162-1)