Impact
The vulnerability is a path traversal that allows a malicious user who can create or modify Dashboard or LibraryPanel resources to retrieve the Grafana Operator manager service account token, potentially enabling privilege escalation within the cluster. Based on the summary provided, it is inferred that an attacker can obtain this token and use it to attain operator‑level access. The Grafana Operator version 5.24.0 contains the fix for this issue.
Affected Systems
Vendor Grafana, product Grafana Operator, versions 5.23 and earlier are impacted. The issue was addressed in version 5.24.0.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. Based on the summary, the attacker requires permissions to create or modify GrafanaDashboards or GrafanaLibraryPanels, implying at least cluster‑level or namespace‑level permissions. Successful exploitation would provide the attacker with a token that has operator privileges, potentially enabling broad cluster access.
OpenCVE Enrichment
Github GHSA