grafana-enterprise is vulnerable to Improper Isolation or Compartmentalization
51
Medium Risk
Affected versions of this package are vulnerable to improper isolation and compartmentalization of permissions. In Grafana, incorrect permissions are applied to the alert rule write API endpoint, allowing users who have permission to write external alert instances to also modify alert rules. This flaw compromises the principle of least privilege by granting users unintended access, potentially leading to unauthorized changes in alert configurations and impacting the reliability and security of the monitoring system.
You are affected if you are using a version which is within vulnerability ranges
grafana-enterprise is vulnerable to Improper Isolation or Compartmentalization in versions 8.5.0 - 10.3.9, 10.4.0 - 10.4.8, 11.0.0 - 11.0.4, 11.1.0 - 11.1.5 and 11.2.0 - 11.2.0.
Upgrade the grafana-enterprise library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant