CVE-2021-28147

Related Vulnerabilities: CVE-2021-28147  

A flaw was found in Grafana Enterprise. An authenticated user can add an external group to an existing team when the editorsCanAdmin feature is enabled. The highest threat from this vulnerability is to data confidentiality.

Description

A flaw was found in Grafana Enterprise. An authenticated user can add an external group to an existing team when the editorsCanAdmin feature is enabled. The highest threat from this vulnerability is to data confidentiality.

Statement

Red Hat products do not ship Grafana Enterprise version, therefore they are not affected by this vulnerability.

Red Hat products do not ship Grafana Enterprise version, therefore they are not affected by this vulnerability.

Additional Information

  • Bugzilla 1938978: CVE-2021-28147 grafana: Allows to bypass access control restrictions via external groups
  • (CWE-287|CWE-863): Improper Authentication or Incorrect Authorization
  • FAQ: Frequently asked questions about CVE-2021-28147