Логотип exploitDog
bind:"GHSA-xfc5-hp99-89qr" OR bind:"CVE-2021-28146"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-xfc5-hp99-89qr" OR bind:"CVE-2021-28146"

Количество 9

Количество 9

github логотип

GHSA-xfc5-hp99-89qr

около 3 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: Низкий
ubuntu логотип

CVE-2021-28146

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-28146

больше 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-28146

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-28146

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2675-1

почти 4 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2662-1

почти 4 года назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1162-1

почти 4 года назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1148-1

почти 4 года назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xfc5-hp99-89qr

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-28146

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2675-1

Security update for SUSE Manager Client Tools

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:2662-1

Security update for grafana

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1162-1

Security update for SUSE Manager Client Tools

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:1148-1

Security update for grafana

почти 4 года назад

Уязвимостей на страницу