First published: Mon Mar 22 2021(Updated: )
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grafana Grafana | >=7.2.0<7.3.10 | |
Grafana Grafana | >=7.4.0<7.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-27962.
The severity of CVE-2021-27962 is high.
Grafana Enterprise versions 7.2.x and 7.3.x before 7.3.10 and versions 7.4.x before 7.4.5 are affected.
An attacker who exploits CVE-2021-27962 can bypass a permission check on a data source they should not be able to access.
To fix CVE-2021-27962, upgrade your Grafana Enterprise installation to version 7.3.10 or 7.4.5 or later.