No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2596 | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource. |
Github GHSA |
GHSA-hh8p-374f-qgr5 | Grafana plugin data sources vulnerable to access control bypass |
Thu, 30 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 03 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource. | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-11-23T15:33:04.210Z
Reserved: 2024-06-25T13:25:06.436Z
Link: CVE-2024-6322
Updated: 2024-09-03T17:04:35.433Z
Status : Awaiting Analysis
Published: 2024-08-20T18:15:09.900
Modified: 2025-10-30T18:15:31.740
Link: CVE-2024-6322
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:16:22Z
EUVD
Github GHSA