CVE-2024-1313 Information
Description
It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/
Grafana Labs would like to thank Ravid Mazon and Jay Chen of Palo Alto Research for discovering and disclosing this vulnerability.
This issue affects Grafana: from 9.5.0 before 9.5.18 from 10.0.0 before 10.0.13 from 10.1.0 before 10.1.9 from 10.2.0 before 10.2.6 from 10.3.0 before 10.3.5.
Reference
https://grafana.com/security/security-advisories/cve-2024-1313/
Share on: