Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3j8x-8x9q-3m4r

Опубликовано: 26 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

EPSS

Процентиль: 16%
0.00052
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-653

Связанные уязвимости

ubuntu
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

CVSS3: 4.7
redhat
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

nvd
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

debian
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write AP ...

CVSS3: 4.1
fstec
10 месяцев назад

Уязвимость реализации прикладного программного интерфейса Endpoint платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 16%
0.00052
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-653