QID 150828
Date Published: 2024-03-11
QID 150828: Grafana Data Source Permission Escalation Vulnerability (CVE-2024-1442)
Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
In installed version of Grafana, if a user can create a data source using Grafana API with UID set to '*', they get full control over reading, querying, editing, and deleting all organization data sources.
Affected Versions:
Grafana 10.3.0 to Grafana 10.3.4
Grafana 10.2.0 to Grafana 10.2.5
Grafana 10.1.0 to Grafana 10.1.8
Grafana 10.0.0 to Grafana 10.0.12
All versions older than Grafana 9.5.17
QID Detection Logic :
This QID sends a HTTP GET request to '/login' or '/api/health' endpoint to retrieve vulnerable version of Grafana running on the target application.
This vulnerability lets a user, with data source creation permission in an organization, access and manipulate any existing data source by querying, editing, sharing, and deleting within that organization.
- CVE-2024-1442 -
grafana.com/security/security-advisories/cve-2024-1442/
CVEs related to QID 150828
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-1442 |
|