In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Sep 2024 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Thu, 26 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 26 Sep 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules. | |
Title | Grafana alerting wrong permission on datasource rule write endpoint | |
Weaknesses | CWE-653 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GRAFANA
Published: 2024-09-26T18:46:07.048Z
Updated: 2024-09-26T19:06:40.196Z
Reserved: 2024-08-23T13:45:00.173Z
Link: CVE-2024-8118
Vulnrichment
Updated: 2024-09-26T19:06:37.257Z
NVD
Status : Awaiting Analysis
Published: 2024-09-26T19:15:07.663
Modified: 2024-09-30T12:46:20.237
Link: CVE-2024-8118
Redhat