Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-28147
HistoryMar 22, 2021 - 12:00 a.m.

CVE-2021-28147

2021-03-2200:00:00
ubuntu.com
ubuntu.com
12
grafana
http api
cve-2021-28147
incorrect access control
external authentication
editorscanadmin

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

41.1%

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before
7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On
Grafana instances using an external authentication service and having the
EditorsCanAdmin feature enabled, this vulnerability allows any
authenticated user to add external groups to any existing team. This can be
used to grant a user team permissions that the user isn’t supposed to have.

Notes

Author Note
avital only affects the enterprise grafana version

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

41.1%