We found results for “”
CVE-2024-9476
Good to know:
Date: November 13, 2024
A privilege escalation vulnerability was discovered in self-managed Grafana OSS v11.2 and Grafana Enterprise v11.2 during routine internal testing. The vulnerability allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.
Language: Go
Severity Score
Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | HIGH |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | NONE |