Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-8118

Опубликовано: 26 сент. 2024
Источник: redhat
CVSS3: 4.7

Описание

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

A flaw was found in Grafana. The wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10grafanaWill not fix
Red Hat Enterprise Linux 8grafanaWill not fix
Red Hat Enterprise Linux 9grafanaWill not fix
Red Hat Storage 3grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2314990grafana: wrong permission is applied to the alert rule write API endpoint

4.7 Medium

CVSS3

Связанные уязвимости

ubuntu
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

nvd
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

debian
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write AP ...

github
10 месяцев назад

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

CVSS3: 4.1
fstec
10 месяцев назад

Уязвимость реализации прикладного программного интерфейса Endpoint платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю повысить свои привилегии

4.7 Medium

CVSS3