6.5
CVSSv3

CVE-2021-28146

Published: 22/03/2021 Updated: 26/03/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The team sync HTTP API in Grafana Enterprise 7.4.x prior to 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grafana grafana

Mailing Lists

Dear all, We have released Grafana 745, 7310 and 676 with important security fixes for all Grafana Enterprise versions from 610-beta1 through 744 Grafana OSS is not affected, as it does not use the features affected by vulnerabilities *Remote Escalation of Privileges vulnerability (CVE-2021-27962)* On the 26th of February during an ...