Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-06914
HistoryNov 17, 2021 - 12:00 a.m.

Grafana has an unspecified vulnerability

2021-11-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
grafana
open source
monitoring tool
vulnerability
fine-grained access control

EPSS

0.003

Percentile

70.0%

Grafana is an open source monitoring tool from Grafana Labs that provides a visual monitoring interface. The tool is primarily used to monitor and analyze Graphite, InfluxDB, Prometheus, etc. A security vulnerability exists in Grafana that stems from the fact that in the affected version, when the fine-grained access control beta feature is enabled and there are multiple organizations in the Grafana instance, administrators can access users from other organizations. An attacker could exploit this vulnerability to list, add, delete, and update user roles in other organizations that do not have an organization administrator role.