Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-9476

Nov. 21, 2024, 5:15 p.m.

Product(s) Impacted

Grafana

Description

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance.

Weaknesses

CWE-266
Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

CWE ID: 266

Date

Published: Nov. 13, 2024, 5:15 p.m.

Last Modified: Nov. 21, 2024, 5:15 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@grafana.com

References

https://grafana.com/ security@grafana.com

https://grafana.com/ security@grafana.com