QID 730289
Date Published: 2021-12-06
QID 730289: Grafana Enterprise Incorrect Access Control Vulnerability
Grafana is an open-source, general purpose dashboard and graph composer, which runs as a web application.
Affected By Below Vulnerabilies:
CVE-2021-41244: In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations.
Affected Versions:
Grafana Version 8.0.0 to 8.2.3
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Grafana Enterprise from the server response
Successful exploitation could allows users with the Organization Admin role to list, add, remove, and update users roles in other organizations in which they are not an admin.
Workaround:
If you cannot upgrade, you should turn off the fine-grained access control using a feature flag.
- Grafana Advisory -
grafana.com/blog/2021/11/15/grafana-8.2.4-released-with-security-fixes/
CVEs related to QID 730289
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-41244 |
|