Grafana is vulnerable to Authorization Bypass
50
Medium Risk
This vulnerability, which was discovered while reviewing a pull request from an external contributor, effects Grafana's data source proxy API and allows authorization checks to be bypassed by adding an extra slash character (/) in the URL path. Among Grafana-maintained data sources, the vulnerability only affects the read paths of Prometheus (all flavors) and Alertmanager when configured with basic authorization.
You are affected if you are using a version that falls within the vulnerable range.
Grafana is vulnerable to Authorization Bypass in versions 8.0.0 - 10.4.17, 11.0.0 - 11.2.8, 11.3.0 - 11.3.5, 11.4.0 - 11.4.3, 11.5.0 - 11.5.3 and 11.6.0 - 11.6.0.
Upgrade the Grafana library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant