Security Advisory

CVE-2024-1442

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-03-07 17:45:43
Last updated 2024-11-22 12:04:45
Assigner GRAFANA
CVSS score 6.0
State PUBLISHED

Description

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.