Описание
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
A flaw in Grafana's public dashboard deletion endpoint lacks organization isolation, allowing an Organization Administrator to delete public dashboards in other organizations using the target dashboard's ID.
Отчет
This Low impact flaw in Grafana allows an authenticated Organization Administrator to delete public dashboards belonging to other organizations. This is due to insufficient isolation enforcement in the public dashboard deletion endpoint, potentially affecting the availability of dashboards in multi-organizational Grafana deployments.
Меры по смягчению последствий
Since this vulnerability only affects the Public Dashboards feature, environments that do not utilize public dashboards can completely neutralize the risk by disabling the feature. This removes the vulnerable endpoint from the attack surface entirely.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Not affected | ||
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Not affected | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Not affected | ||
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Not affected | ||
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Not affected | ||
| Red Hat Ceph Storage 9 | rhceph/grafana-rhel10 | Not affected | ||
| Red Hat Enterprise Linux 10 | grafana | Not affected | ||
| Red Hat Enterprise Linux 8 | grafana | Not affected | ||
| Red Hat Enterprise Linux 9 | grafana | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
EPSS
3.1 Low
CVSS3