Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2596 | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource. |
Github GHSA |
GHSA-hh8p-374f-qgr5 | Grafana plugin data sources vulnerable to access control bypass |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 30 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 03 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource. | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-10-30T17:55:02.115Z
Reserved: 2024-06-25T13:25:06.436Z
Link: CVE-2024-6322
Updated: 2024-09-03T17:04:35.433Z
Status : Awaiting Analysis
Published: 2024-08-20T18:15:09.900
Modified: 2025-10-30T18:15:31.740
Link: CVE-2024-6322
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:16:22Z
EUVD
Github GHSA