Логотип exploitDog
bind:"GHSA-jfp3-g5xg-h74p" OR bind:"CVE-2021-28147"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-jfp3-g5xg-h74p" OR bind:"CVE-2021-28147"

Количество 9

Количество 9

github логотип

GHSA-jfp3-g5xg-h74p

больше 3 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-28147

почти 5 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-28147

почти 5 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-28147

почти 5 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-28147

почти 5 лет назад

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x bef ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2675-1

больше 4 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2662-1

больше 4 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1162-1

больше 4 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1148-1

больше 4 лет назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-jfp3-g5xg-h74p

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-28147

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x bef ...

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2675-1

Security update for SUSE Manager Client Tools

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2662-1

Security update for grafana

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1162-1

Security update for SUSE Manager Client Tools

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1148-1

Security update for grafana

больше 4 лет назад

Уязвимостей на страницу