Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfc5-hp99-89qr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
redhat
больше 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
nvd
около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
debian
около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an ...

suse-cvrf
почти 4 года назад

Security update for SUSE Manager Client Tools

EPSS

Процентиль: 50%
0.00265
Низкий

Дефекты

CWE-863