Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8118

Опубликовано: 26 сент. 2024
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

A flaw was found in Grafana. The wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8grafanaWill not fix
Red Hat Enterprise Linux 9grafanaWill not fix
Red Hat Storage 3grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2314990grafana: wrong permission is applied to the alert rule write API endpoint

EPSS

Процентиль: 9%
0.00036
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

ubuntu
9 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

nvd
9 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

debian
9 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write AP ...

github
9 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

CVSS3: 4.1
fstec
9 месяцев назад

Уязвимость реализации прикладного программного интерфейса Endpoint платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 9%
0.00036
Низкий

4.7 Medium

CVSS3