Grafana is vulnerable to Authorization Bypass
50
Medium Risk
This vulnerability, which was discovered while reviewing a pull request from an external contributor, effects Grafana's data source proxy API and allows authorization checks to be bypassed by adding an extra slash character (/) in the URL path. Among Grafana-maintained data sources, the vulnerability only affects the read paths of Prometheus (all flavors) and Alertmanager when configured with basic authorization.
You are affected if you are using a version that falls within the vulnerable range.
Grafana is vulnerable to Authorization Bypass in versions 8.0.0 - 10.4.17, 11.0.0 - 11.2.8, 11.3.0 - 11.3.5, 11.4.0 - 11.4.3, 11.5.0 - 11.5.3 and 11.6.0 - 11.6.0.
Upgrade the Grafana library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant