CVE-2024-8118
Sept. 30, 2024, 12:46 p.m.
Tags
Product(s) Impacted
Grafana
Description
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
Weaknesses
CWE-653
Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
CWE ID: 653Date
Published: Sept. 26, 2024, 7:15 p.m.
Last Modified: Sept. 30, 2024, 12:46 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
security@grafana.com
References
https://grafana.com/
security@grafana.com