CVE-2023-4822
Grafana privilege escalation vulnerability
描述
Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization Admin roles in all organizations.It also allows an Organization Admin to assign or revoke any permissions that they have to any user globally.This means that any Organization Admin can elevate their own permissions in any organization that they are already a member of, or elevate or restrict the permissions of any other user.The vulnerability does not allow a user to become a member of an organization that they are not already a member of, or to add any other users to an organization that the current user is not a member of.
如何修補 CVE-2023-4822
要修補 CVE-2023-4822,請將受影響套件升級到下列已修補版本。
- —升級至 9.4.16 或更新版本
- —未列出修補版本
CVE-2023-4822 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 8.0.0, < 9.4.16, >= 9.5.0, < 9.5.11, >= 10.0.0, < 10.0.7, >= 10.1.0, < 10.1.3 | >= 10.1.4, <= 10.1.4
- from 0, <= 10.1.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.7 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L |