CVE-2024-1313Medium· 6.5▾ SunlitA vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a vie…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
Last analysed / modified upstream
A vulnerability was found in Grafana. Due to an error in authorization logic, it is possible for an unprivileged user in a different organization other than the snapshot owner to perform unauthorized actions such as deleting it using a view key.
grafana: vulnerable to authorization bypass — rated Moderate by Red Hat. Released 2024-03-26, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2024:3265 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2024:2568
Workarounds / mitigations:
Affected packages:
github.com/grafana/grafana >= 9.5.0, < 9.5.18github.com/grafana/grafana >= 10.0.0, < 10.0.13github.com/grafana/grafana >= 10.1.0, < 10.1.9github.com/grafana/grafana >= 10.2.0, < 10.2.6github.com/grafana/grafana >= 10.3.0, < 10.3.5Patched in:
github.com/grafana/grafana 9.5.18github.com/grafana/grafana 10.0.13github.com/grafana/grafana 10.1.9github.com/grafana/grafana 10.2.6github.com/grafana/grafana 10.3.5Connected by shared product, vendor, weakness, or advisory.
CVE-2022-3064High· 7.5go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)
CVE-2026-42501Medium· 5.3cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501)
CVE-2026-39817Medium· 5.9cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817)
CVE-2026-39819Medium· 4.4cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819)
CVE-2026-34972Medium· 4.2github.com/openfga/openfga: OpenFGA: Improper policy enforcement via specific BatchCheck calls (CVE-2026-34972)
CVE-2026-44431Medium· 5.3urllib3 is an HTTP client library for Python