Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37222
HistorySep 21, 2022 - 7:49 a.m.

Privilege Escalation

2022-09-2107:49:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29
grafana
privilege escalation
fake datasource

EPSS

0.003

Percentile

68.6%

github.com/grafana/grafana is vulnerable to privilege escalation. A remote admin is able to take over the server admin account and gain full control of the particular grafana instance when auth proxy is used, via calling a fake datasource publicly through this proxying feature.