Impact
The Grafana Operator contains a path traversal flaw that could be exploited to gain privilege escalation. According to the advisory, this flaw may enable an attacker to access the Grafana Operator manager’s service account token, potentially granting operator-level privileges within the cluster.
Affected Systems
Vendor Grafana, product Grafana Operator, versions 5.23 and earlier are impacted. The issue was addressed in version 5.24.0.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker needs the ability to create or modify GrafanaDashboards or GrafanaLibraryPanels, which typically requires at least namespace‑level or cluster‑level permissions. Successful exploitation would provide the attacker with the Grafana Operator manager’s service account token, granting operator‑level privileges within the cluster.
OpenCVE Enrichment
Github GHSA