QID 980094

QID 980094: Go (go) Security Update for github.com/grafana/grafana (GHSA-69j6-29vr-p3j9)

Security update has been released for github.com/grafana/grafana to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths:

* `/dashboard/snapshot/:key`, or
* `/api/snapshots/:key`

If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path:

* `/api/snapshots-delete/:deleteKey`

Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths:

* `/api/snapshots/:key`, or
* `/api/snapshots-delete/:deleteKey`

The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-69j6-29vr-p3j9 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980094

    Software Advisories
    Advisory ID Software Component Link
    GHSA-69j6-29vr-p3j9 github.com/grafana/grafana URL Logo github.com/advisories/GHSA-69j6-29vr-p3j9