A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.
Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0834 | A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization. |
Github GHSA |
GHSA-5mxf-42f5-j782 | Grafana's users with permissions to create a data source can CRUD all data sources |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 11 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana grafana |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Grafana
Grafana grafana |
Fri, 22 Nov 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Nov 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat acm
|
|
| CPEs | cpe:/a:redhat:acm:2.12::el9 | |
| Vendors & Products |
Redhat acm
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2024-11-22T12:04:45.739Z
Reserved: 2024-02-12T12:21:26.806Z
Link: CVE-2024-1442
Updated: 2024-11-22T12:04:45.739Z
Status : Analyzed
Published: 2024-03-07T18:15:46.590
Modified: 2025-03-11T16:56:13.943
Link: CVE-2024-1442
OpenCVE Enrichment
No data.
EUVD
Github GHSA