Incorrect Privilege Assignment
CVE-2024-9476
Summary
A vulnerability in Grafana Labs, Grafana OSS and Enterprise allows Privilege Escalation which allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant. This vulnerability will only affect users who utilize the organization's feature to isolate resources on their Grafana instance. This issue affects Grafana versions 11.2.0 through v11.2.3 and 11.3.0.
- LOW
- LOCAL
- NONE
- UNCHANGED
- REQUIRED
- HIGH
- HIGH
- NONE
CWE-266 - Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
References
Advisory Timeline
- Published