{"id":"CVE-2024-1442","title":"grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)","summary":"A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…","severity":"medium","cvss":6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L","cvssSource":"vendor","cwe":"CWE-269","vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9","affected":["ceph_storage 4","ceph_storage 5","ceph_storage 7","storage 3","advanced_cluster_management_for_kubernetes_2_12_for_rhel 9","ceph_storage_6_1_tools"],"patched":["advanced_cluster_management_for_kubernetes_2_12_for_rhel 9","ceph_storage_6_1_tools"],"published":"2024-03-07","updated":"2026-09-17","sourceUpdated":"2026-09-17T12:15:42+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1442.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1442.json"},{"url":"https://access.redhat.com/security/cve/CVE-2024-1442"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2268486"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-1442"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1442"},{"url":"https://github.com/advisories/GHSA-5mxf-42f5-j782"},{"url":"https://access.redhat.com/errata/RHSA-2024:8974"},{"url":"https://access.redhat.com/errata/RHSA-2024:2633"},{"url":"https://github.com/grafana/grafana"},{"url":"https://grafana.com/security/security-advisories/cve-2024-1442"},{"url":"https://security.netapp.com/advisory/ntap-20241122-0007"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00802,"epssPercentile":0.54686,"aliases":["GHSA-5mxf-42f5-j782","BIT-grafana-2024-1442","GO-2024-2629"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.756Z","slug":"CVE-2024-1442","body":"## Overview\n\nA flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized access to read, query, edit, and delete all data sources within the organization. Such unrestricted access can lead to data breaches, manipulation, privacy violations, and compliance issues, emphasizing the critical importance of implementing stringent access controls and monitoring API usage.\n\n## Vendor advisories\n\n- **RHSA-2024:8974** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 · released 2024-11-06 · [advisory](https://access.redhat.com/errata/RHSA-2024:8974)\n- **RHSA-2024:2633** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2024-05-01 · [advisory](https://access.redhat.com/errata/RHSA-2024:2633)\n- **Red Hat VEX** · Moderate · affected: Red Hat Ceph Storage 4, Red Hat Ceph Storage 5, Red Hat Ceph Storage 7, Red Hat Storage 3 · no fix planned: Red Hat Ceph Storage 4, Red Hat Storage 3, Red Hat Ceph Storage 5, Red Hat Ceph Storage 7 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1442.json)\n\n**grafana: Improper priviledge managent for users with data source permissions** — rated Moderate by Red Hat. Released 2024-03-07, updated 2026-09-17.\n\nAffected:\n\n- Red Hat Ceph Storage 4\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 7\n- Red Hat Storage 3\n\nFixed:\n\n- Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9\n- Red Hat Ceph Storage 6.1 Tools\n\nNo fix planned:\n\n- Red Hat Ceph Storage 4\n- Red Hat Storage 3\n- Red Hat Ceph Storage 5\n- Red Hat Ceph Storage 7\n\nNot affected:\n\n- Red Hat Ceph Storage 6.1 Tools\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 3.11\n\n## Remediation\n\nFor Red Hat Advanced Cluster Management for Kubernetes, see the following documentation for details on how to install the images: \n\nhttps://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/install/installing https://access.redhat.com/errata/RHSA-2024:8974\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258\n\nand\n\nhttps://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6\n\nFor supported configurations, refer to:\n\nhttps://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:2633\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2024-1442)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 8.5.0, < 9.5.7`\n- `github.com/grafana/grafana >= 10.0.0, < 10.0.12`\n- `github.com/grafana/grafana >= 10.1.0, < 10.1.8`\n- `github.com/grafana/grafana >= 10.2.0, < 10.2.5`\n- `github.com/grafana/grafana >= 10.3.0, < 10.3.4`\n\nPatched in:\n\n- `github.com/grafana/grafana 9.5.7`\n- `github.com/grafana/grafana 10.0.12`\n- `github.com/grafana/grafana 10.1.8`\n- `github.com/grafana/grafana 10.2.5`\n- `github.com/grafana/grafana 10.3.4`\n\nSource: https://osv.dev/vulnerability/GHSA-5mxf-42f5-j782","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}