{"id":"CVE-2023-4822","title":"grafana: incorrect assessment of permissions across organizations (CVE-2023-4822)","summary":"A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permis…","severity":"medium","cvss":6.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L","cvssSource":"vendor","vendor":"Red Hat","product":"Red Hat Ceph Storage 7.1 Tools","affected":["ceph_storage_7_1_tools"],"patched":["ceph_storage_7_1_tools"],"published":"2023-10-12","updated":"2026-09-17","sourceUpdated":"2026-09-17T13:33:01+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4822.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4822.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-4822"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2239726"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-4822"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4822"},{"url":"https://grafana.com/blog/2023/10/13/grafana-security-release-new-versions-of-grafana-with-a-medium-severity-security-fix-for-cve-2023-4822/"},{"url":"https://access.redhat.com/errata/RHSA-2024:3925"},{"url":"https://github.com/grafana/grafana"},{"url":"https://grafana.com/security/security-advisories/cve-2023-4822"},{"url":"https://security.netapp.com/advisory/ntap-20231103-0008"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.01074,"epssPercentile":0.63039,"aliases":["GHSA-fw9c-75hh-89p6","BIT-grafana-2023-4822"],"ecosystem":"go","ingestedAt":"2026-08-07T19:14:16.734Z","slug":"CVE-2023-4822","body":"## Overview\n\nA flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permissions and global role assignments. After successful exploitation, an attacker who has the Organization Admin role in any organization can elevate their permissions across all organizations, elevate other users’ permissions in all organizations, or limit other users’ permissions in all organizations.\n\n## Vendor advisories\n\n- **RHSA-2024:3925** · Red Hat · fixed in: Red Hat Ceph Storage 7.1 Tools · released 2024-06-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:3925)\n\n**grafana: incorrect assessment of permissions across organizations** — rated Moderate by Red Hat. Released 2023-10-12, updated 2026-09-17.\n\nFixed:\n\n- Red Hat Ceph Storage 7.1 Tools\n\nNot affected:\n\n- Cryostat 2\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 6\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 3.11\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nFor supported configurations, refer to:\n\nhttps://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:3925\n\n## Package advisory (CVE-2023-4822)\n\nAffected packages:\n\n- `github.com/grafana/grafana <= 10.1.5`\n\nSource: https://osv.dev/vulnerability/GHSA-fw9c-75hh-89p6","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}