MEDIUM6.0
GHSA-5mxf-42f5-j782
Grafana's users with permissions to create a data source can CRUD all data sources
Quick fix
GHSA-5mxf-42f5-j782 — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v9.5.7Details
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
8.5.0Fixed in: 9.5.7Fix
go get github.com/grafana/grafana@v9.5.7Go/github.com/grafana/grafana
Introduced in:
10.0.0Fixed in: 10.0.12Fix
go get github.com/grafana/grafana@v10.0.12Go/github.com/grafana/grafana
Introduced in:
10.1.0Fixed in: 10.1.8Fix
go get github.com/grafana/grafana@v10.1.8Go/github.com/grafana/grafana
Introduced in:
10.2.0Fixed in: 10.2.5Fix
go get github.com/grafana/grafana@v10.2.5Go/github.com/grafana/grafana
Introduced in:
10.3.0Fixed in: 10.3.4Fix
go get github.com/grafana/grafana@v10.3.4