CVE-2021-27962: High severity grafana labs grafana oss and enterprise vulnerability
Published Mar 22, 2021
·Updated
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
Affected Software
2 affected components
Grafana Grafana>=7.2.0<7.3.10
Grafana Grafana>=7.4.0<7.4.5
Event History
Mar 22, 2021
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Grafana Enterprise issue?
The vulnerability ID is CVE-2021-27962.
2
What is the severity of CVE-2021-27962?
The severity of CVE-2021-27962 is high.
3
Which versions of Grafana Enterprise are affected by CVE-2021-27962?
Grafana Enterprise versions 7.2.x and 7.3.x before 7.3.10 and versions 7.4.x before 7.4.5 are affected.
4
What can an attacker do if they exploit CVE-2021-27962?
An attacker who exploits CVE-2021-27962 can bypass a permission check on a data source they should not be able to access.
5
How can I fix CVE-2021-27962?
To fix CVE-2021-27962, upgrade your Grafana Enterprise installation to version 7.3.10 or 7.4.5 or later.