---
id: CVE-2024-1442
title: >-
  grafana: Improper priviledge managent for users with data source permissions
  (CVE-2024-1442)
summary: >-
  A flaw was found in Grafana, where setting the Grafana API Data Source UID to
  '*' Grants Unrestricted Access, grants a user the ability to set the UID to
  '*' via the Grafana API poses a severe security risk. This issue enables
  unauthorized…
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'
cvssSource: vendor
cwe: CWE-269
vendor: Red Hat
product: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9
affected:
  - ceph_storage 4
  - ceph_storage 5
  - ceph_storage 7
  - storage 3
  - advanced_cluster_management_for_kubernetes_2_12_for_rhel 9
  - ceph_storage_6_1_tools
patched:
  - advanced_cluster_management_for_kubernetes_2_12_for_rhel 9
  - ceph_storage_6_1_tools
published: '2024-03-07'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T12:15:42+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1442.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1442.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1442'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2268486'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-1442'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1442'
  - url: 'https://github.com/advisories/GHSA-5mxf-42f5-j782'
  - url: 'https://access.redhat.com/errata/RHSA-2024:8974'
  - url: 'https://access.redhat.com/errata/RHSA-2024:2633'
  - url: 'https://github.com/grafana/grafana'
  - url: 'https://grafana.com/security/security-advisories/cve-2024-1442'
  - url: 'https://security.netapp.com/advisory/ntap-20241122-0007'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00802
epssPercentile: 0.54812
aliases:
  - GHSA-5mxf-42f5-j782
  - BIT-grafana-2024-1442
  - GO-2024-2629
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.756Z'
---

## Overview

A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized access to read, query, edit, and delete all data sources within the organization. Such unrestricted access can lead to data breaches, manipulation, privacy violations, and compliance issues, emphasizing the critical importance of implementing stringent access controls and monitoring API usage.

## Vendor advisories

- **RHSA-2024:8974** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 · released 2024-11-06 · [advisory](https://access.redhat.com/errata/RHSA-2024:8974)
- **RHSA-2024:2633** · Red Hat · fixed in: Red Hat Ceph Storage 6.1 Tools · released 2024-05-01 · [advisory](https://access.redhat.com/errata/RHSA-2024:2633)
- **Red Hat VEX** · Moderate · affected: Red Hat Ceph Storage 4, Red Hat Ceph Storage 5, Red Hat Ceph Storage 7, Red Hat Storage 3 · no fix planned: Red Hat Ceph Storage 4, Red Hat Storage 3, Red Hat Ceph Storage 5, Red Hat Ceph Storage 7 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1442.json)

**grafana: Improper priviledge managent for users with data source permissions** — rated Moderate by Red Hat. Released 2024-03-07, updated 2026-09-17.

Affected:

- Red Hat Ceph Storage 4
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 7
- Red Hat Storage 3

Fixed:

- Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9
- Red Hat Ceph Storage 6.1 Tools

No fix planned:

- Red Hat Ceph Storage 4
- Red Hat Storage 3
- Red Hat Ceph Storage 5
- Red Hat Ceph Storage 7

Not affected:

- Red Hat Ceph Storage 6.1 Tools
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 3.11

## Remediation

For Red Hat Advanced Cluster Management for Kubernetes, see the following documentation for details on how to install the images: 

https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/install/installing https://access.redhat.com/errata/RHSA-2024:8974
Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

and

https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6

For supported configurations, refer to:

https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:2633

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2024-1442)

Affected packages:

- `github.com/grafana/grafana >= 8.5.0, < 9.5.7`
- `github.com/grafana/grafana >= 10.0.0, < 10.0.12`
- `github.com/grafana/grafana >= 10.1.0, < 10.1.8`
- `github.com/grafana/grafana >= 10.2.0, < 10.2.5`
- `github.com/grafana/grafana >= 10.3.0, < 10.3.4`

Patched in:

- `github.com/grafana/grafana 9.5.7`
- `github.com/grafana/grafana 10.0.12`
- `github.com/grafana/grafana 10.1.8`
- `github.com/grafana/grafana 10.2.5`
- `github.com/grafana/grafana 10.3.4`

Source: https://osv.dev/vulnerability/GHSA-5mxf-42f5-j782
