Intel

AIKIDO-2024-10460

grafana-enterprise is vulnerable to Incorrect Privilege Assignment

Incorrect Privilege AssignmentCVE-2024-9476 Published Nov 20, 2024

53

Medium Risk

This Affects:

osgrafana-enterprise
11.2.0 - 11.2.3
Fixed in 11.2.4
11.3.0 - 11.3.0
Fixed in 11.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper privilege assignment, leading to potential privilege escalation. In self-managed Grafana OSS v11.2 and Grafana Enterprise v11.2, a vulnerability was identified during routine internal testing. This flaw allows users to access resources belonging to other organizations within the same Grafana instance by exploiting the Grafana Cloud Migration Assistant, undermining organizational boundaries and security controls.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

grafana-enterprise is vulnerable to Incorrect Privilege Assignment in versions 11.2.0 - 11.2.3 and 11.3.0 - 11.3.0.

How to fix this

Upgrade the grafana-enterprise library to a patch version.