Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.145676
Category:General
Title:Grafana 6.1.0-beta1 - 7.4.3 Access Control Bypass Vulnerability
Summary:Grafana is prone to an access control bypass vulnerability.
Description:Summary:
Grafana is prone to an access control bypass vulnerability.

Vulnerability Insight:
The team sync HTTP API in Grafana Enterprise has an incorrect access
control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin
feature enabled, this vulnerability allows any authenticated user to add external groups to any existing
team. This can be used to grant a user team permissions that the user isn't supposed to have.

Affected Software/OS:
Grafana version 6.1.0-beta1 through 7.4.4.

Solution:
Update to version 6.7.6, 7.3.10, 7.4.5 or later.

CVSS Score:
3.5

CVSS Vector:
AV:N/AC:M/Au:S/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-28147
https://community.grafana.com/t/grafana-enterprise-6-7-6-7-3-10-and-7-4-5-security-update/44724
https://community.grafana.com/t/release-notes-v6-7-x/27119
https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-3-10/
https://grafana.com/docs/grafana/latest/release-notes/release-notes-7-4-5/
https://grafana.com/products/enterprise/
https://www.openwall.com/lists/oss-security/2021/03/19/5
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.