CVE Vulnerabilities

CVE-2021-27962

Published: Mar 22, 2021 | Modified: Jul 12, 2022
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
6.8 IMPORTANT
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Ubuntu
MEDIUM

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

Affected Software

Name Vendor Start Version End Version
Grafana Grafana 7.2.0 (including) 7.3.10 (excluding)
Grafana Grafana 7.4.0 (including) 7.4.5 (excluding)
Grafana Ubuntu trusty *

References