Published: 22/03/2021 Updated: 26/03/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

The team sync HTTP API in Grafana Enterprise 7.4.x prior to 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

grafana grafana

Mailing Lists

Dear all, We have released Grafana 745, 7310 and 676 with important security fixes for all Grafana Enterprise versions from 610-beta1 through 744 Grafana OSS is not affected, as it does not use the features affected by vulnerabilities *Remote Escalation of Privileges vulnerability (CVE-2021-27962)* On the 26th of February during an ...