Логотип exploitDog
bind:CVE-2024-6322
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6322

Количество 4

Количество 4

ubuntu логотип

CVE-2024-6322

больше 1 года назад

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-6322

больше 1 года назад

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-6322

больше 1 года назад

Access control for plugin data sources protected by the ReqActions jso ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hh8p-374f-qgr5

больше 1 года назад

Grafana plugin data sources vulnerable to access control bypass

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-6322

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6322

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6322

Access control for plugin data sources protected by the ReqActions jso ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-hh8p-374f-qgr5

Grafana plugin data sources vulnerable to access control bypass

CVSS3: 4.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу