icon

We found results for “

CVE-2024-9476

Good to know:

icon
icon

Date: November 13, 2024

A privilege escalation vulnerability was discovered in self-managed Grafana OSS v11.2 and Grafana Enterprise v11.2 during routine internal testing. The vulnerability allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.

Language: Go

Severity Score

Weakness Type (CWE)

Improper Privilege Management

CWE-269

Incorrect Privilege Assignment

CWE-266

Top Fix

icon

Upgrade Version

Upgrade to version github.com/grafana/grafana-v11.3.0+security-01

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us