Access Restriction Bypass Affecting github.com/grafana/grafana package, versions >=8.0.0 <8.2.4
Threat Intelligence
EPSS
0.31% (71st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMGRAFANAGRAFANA-1921106
- published 16 Nov 2021
- disclosed 16 Nov 2021
- credit Unknown
Introduced: 16 Nov 2021
CVE-2021-41244 Open this link in a new tabHow to fix?
Upgrade github.com/grafana/grafana
to version 8.2.4 or higher.
Overview
Affected versions of this package are vulnerable to Access Restriction Bypass via the fine-grained access control
beta feature, which allows Grafana admins to access other users in other organizations in the instance in which they are not admins. If you cannot upgrade, you should turn off the fine-grained access control using a feature flag.
References
CVSS Scores
version 3.1