CVE-2024-8118

Source
https://cve.org/CVERecord?id=CVE-2024-8118
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8118.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-8118
Aliases
Downstream
Related
Published
2024-09-26T18:46:07.048Z
Modified
2026-08-12T03:51:15.356448339Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Grafana alerting wrong permission on datasource rule write endpoint
Details

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

Database specific
{
    "cna_assigner": "GRAFANA",
    "cwe_ids": [
        "CWE-653"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8118.json"
}
References

Affected packages

Git / github.com/grafana/grafana

Affected ranges

Type
GIT
Repo
https://github.com/grafana/grafana
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "8.5.0"
        },
        {
            "fixed": "10.3.10"
        },
        {
            "introduced": "10.4.0"
        },
        {
            "fixed": "10.4.9"
        },
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.0.5"
        },
        {
            "introduced": "11.1.0"
        },
        {
            "fixed": "11.1.6"
        },
        {
            "introduced": "11.2.0"
        },
        {
            "fixed": "11.2.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v11.*
v11.0.0
v11.0.1
v11.0.2
v11.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8118.json"