CVE-2024-1442: User with permissions to create a data source can CRUD all data sources
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to . Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1442?
CVE-2024-1442 is classified as a high-severity vulnerability due to its potential to grant unauthorized access to all data sources within the organization.
How do I fix CVE-2024-1442?
To remediate CVE-2024-1442, update Grafana to version 10.3.4, 10.2.5, 10.1.8, or 10.0.12.
What versions of Grafana are affected by CVE-2024-1442?
CVE-2024-1442 affects Grafana versions from 9.5.0 up to 10.3.4, including specific sub-versions noted in the vulnerability details.
Can an attacker exploit CVE-2024-1442 remotely?
Yes, an attacker with permissions to create a data source can exploit CVE-2024-1442 remotely via the Grafana API.
What are the consequences of CVE-2024-1442 if exploited?
Exploitation of CVE-2024-1442 could allow unauthorized users to read, query, edit, and delete all data sources within the targeted Grafana organization.