QID 997682
Date Published: 2024-03-13
QID 997682: GO (Go) Security Update for github.com/grafana/grafana (GHSA-5mxf-42f5-j782)
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5mxf-42f5-j782 for updates and patch information.
Vendor References
- GHSA-5mxf-42f5-j782 -
github.com/advisories/GHSA-5mxf-42f5-j782
CVEs related to QID 997682
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5mxf-42f5-j782 | github.com/grafana/grafana |
|