VDB
Sign up
MEDIUM6.0

GHSA-5mxf-42f5-j782

Grafana's users with permissions to create a data source can CRUD all data sources

Quick fix

GHSA-5mxf-42f5-j782 — github.com/grafana/grafana: upgrade to the fixed version with the command below.

go get github.com/grafana/grafana@v9.5.7

Details

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/grafana/grafana
Introduced in: 8.5.0Fixed in: 9.5.7
Fixgo get github.com/grafana/grafana@v9.5.7
Go/github.com/grafana/grafana
Introduced in: 10.0.0Fixed in: 10.0.12
Fixgo get github.com/grafana/grafana@v10.0.12
Go/github.com/grafana/grafana
Introduced in: 10.1.0Fixed in: 10.1.8
Fixgo get github.com/grafana/grafana@v10.1.8
Go/github.com/grafana/grafana
Introduced in: 10.2.0Fixed in: 10.2.5
Fixgo get github.com/grafana/grafana@v10.2.5
Go/github.com/grafana/grafana
Introduced in: 10.3.0Fixed in: 10.3.4
Fixgo get github.com/grafana/grafana@v10.3.4

References