A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance.
History

Wed, 13 Nov 2024 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance.
Title Privilege escalation vulnerability for Organizations in Grafana
Weaknesses CWE-266
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published: 2024-11-13T16:30:54.581Z

Updated: 2024-11-13T16:30:54.581Z

Reserved: 2024-10-03T12:58:42.842Z

Link: CVE-2024-9476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2024-11-13T17:15:12.747

Modified: 2024-11-13T17:15:12.747

Link: CVE-2024-9476

cve-icon Redhat

No data.