Описание
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Ссылки
- Broken Link
Уязвимые конфигурации
Одно из
EPSS
3.1 Low
CVSS3
2.7 Low
CVSS3
Дефекты
Связанные уязвимости
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с недостатками контроля доступа. Эксплуатация уязвимости может позволить нарушителю повысить свои привилегии
EPSS
3.1 Low
CVSS3
2.7 Low
CVSS3