QID 995594

Date Published: 2023-10-18

QID 995594: GO (Go) Security Update for github.com/grafana/grafana (GHSA-fw9c-75hh-89p6)

Grafana is an open-source platform for monitoring and observability. The vulnerability impacts instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-fw9c-75hh-89p6 for updates and patch information.
    Vendor References

    CVEs related to QID 995594

    Software Advisories
    Advisory ID Software Component Link