CVE-2024-1442: Grafana
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Affected products
- Grafana Grafana: from 8.5.0, before 9.5.7 (fixed in 9.5.7); from 10.0.0, before 10.0.12 (fixed in 10.0.12); from 10.1.0, before 10.1.8 (fixed in 10.1.8); from 10.2.0, before 10.2.5 (fixed in 10.2.5); from 10.3.0, before 10.3.4 (fixed in 10.3.4)
Published 2024-03-07. Last modified 2026-06-17.