CVE-2024-6322

MEDIUM

Grafana 11.1.0-11.1.1 and 11.1.2-11.1.3 - Incorrect Privilege Assignment via ReqActions Bypass

Title source: llm
STIX 2.1

Description

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0031
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266
Status published
Products (5)
grafana/grafana 11.1.0 - 11.1.1Go
Grafana/Grafana 11.1.0 - 11.1.1
Grafana/Grafana 11.1.2 - 11.1.3
Grafana/Grafana Enterprise 11.1.0 - 11.1.1
Grafana/Grafana Enterprise 11.1.2 - 11.1.3
Published Aug 20, 2024
Tracked Since Feb 18, 2026