github.com
https://github.com/grafana/grafana CVE-2024-6322
Grafana plugin data sources vulnerable to access control bypass
Description
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 21, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
GrafanaBrowse Grafana / Grafana | CVE List | 11.1.0 to < 11.1.1 | affected |
| 11.1.2 to < 11.1.3 | affected | ||
Grafana EnterpriseBrowse Grafana / Grafana Enterprise | CVE List | 11.1.0 to < 11.1.1 | affected |
| 11.1.2 to < 11.1.3 | affected | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 11.1.0 | affected |
| 11.1.0 to < 11.1.1 · Fixed in 11.1.1 | affected | ||
| 11.1.2 | affected | ||
| 11.1.2 to < 11.1.3 · Fixed in 11.1.3 | affected | ||
| 0.0.0-20240521130516-0072e4a92d89 to < 0.0.0-20240725142242-c326d865c58b · Fixed in 0.0.0-20240725142242-c326d865c58b | affected | ||
| 1.9.2-0.20240521130516-0072e4a92d89 to < 1.9.2-0.20240725142242-c326d865c58b · Fixed in 1.9.2-0.20240725142242-c326d865c58b | affected |
References
5github.com
https://github.com/grafana/grafana/commit/4cb3ba5d1a7ab8b9676034e89dada2fcde1766ef github.com
https://github.com/grafana/grafana/commit/9cdba084a9100c6b11d32eef9d2bd53656c6964a grafana.com
https://grafana.com/security/security-advisories/cve-2024-6322 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6322