Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2024-50312 | A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 | cvssV3_1 
 | 
Sat, 16 Nov 2024 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | |
| Metrics | threat_severity 
 | threat_severity 
 | 
Thu, 14 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Wed, 13 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance. | |
| Title | Privilege escalation vulnerability for Organizations in Grafana | |
| Weaknesses | CWE-266 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-10-30T17:55:03.339Z
Reserved: 2024-10-03T12:58:42.842Z
Link: CVE-2024-9476
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-14T15:54:23.722Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2024-11-13T17:15:12.747
Modified: 2024-11-21T17:15:28.000
Link: CVE-2024-9476
 Redhat
                        Redhat
                     OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.