---
id: CVE-2023-4822
title: >-
  grafana: incorrect assessment of permissions across organizations
  (CVE-2023-4822)
summary: >-
  A flaw was found in the Grafana enterprise package. Grafana is incorrectly
  assessing permissions to update global roles and role assignments, therefore,
  users with administrator permissions in one organization can change global
  role permis…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L'
cvssSource: vendor
vendor: Red Hat
product: Red Hat Ceph Storage 7.1 Tools
affected:
  - ceph_storage_7_1_tools
patched:
  - ceph_storage_7_1_tools
published: '2023-10-12'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:33:01+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4822.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-4822.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-4822'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2239726'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-4822'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-4822'
  - url: >-
      https://grafana.com/blog/2023/10/13/grafana-security-release-new-versions-of-grafana-with-a-medium-severity-security-fix-for-cve-2023-4822/
  - url: 'https://access.redhat.com/errata/RHSA-2024:3925'
  - url: 'https://github.com/grafana/grafana'
  - url: 'https://grafana.com/security/security-advisories/cve-2023-4822'
  - url: 'https://security.netapp.com/advisory/ntap-20231103-0008'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.01074
epssPercentile: 0.63528
aliases:
  - GHSA-fw9c-75hh-89p6
  - BIT-grafana-2023-4822
ecosystem: go
ingestedAt: '2026-08-07T19:14:16.734Z'
---

## Overview

A flaw was found in the Grafana enterprise package. Grafana is incorrectly assessing permissions to update global roles and role assignments, therefore, users with administrator permissions in one organization can change global role permissions and global role assignments. After successful exploitation, an attacker who has the Organization Admin role in any organization can elevate their permissions across all organizations, elevate other users’ permissions in all organizations, or limit other users’ permissions in all organizations.

## Vendor advisories

- **RHSA-2024:3925** · Red Hat · fixed in: Red Hat Ceph Storage 7.1 Tools · released 2024-06-14 · [advisory](https://access.redhat.com/errata/RHSA-2024:3925)

**grafana: incorrect assessment of permissions across organizations** — rated Moderate by Red Hat. Released 2023-10-12, updated 2026-09-17.

Fixed:

- Red Hat Ceph Storage 7.1 Tools

Not affected:

- Cryostat 2
- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 6
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 3.11
- Red Hat OpenShift Container Platform 4

## Remediation

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

For supported configurations, refer to:

https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:3925

## Package advisory (CVE-2023-4822)

Affected packages:

- `github.com/grafana/grafana <= 10.1.5`

Source: https://osv.dev/vulnerability/GHSA-fw9c-75hh-89p6
