CVE-2024-1313
Users outside an organization can delete a snapshot with its key
描述
It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/<key> using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot in question, but due to a bug in the authorization logic, deletion requests issued by an unprivileged user in a different organization than the snapshot owner are treated as authorized. Grafana Labs would like to thank Ravid Mazon and Jay Chen of Palo Alto Research for discovering and disclosing this vulnerability. This issue affects Grafana: from 9.5.0 before 9.5.18, from 10.0.0 before 10.0.13, from 10.1.0 before 10.1.9, from 10.2.0 before 10.2.6, from 10.3.0 before 10.3.5.
如何修補 CVE-2024-1313
要修補 CVE-2024-1313,請將受影響套件升級到下列已修補版本。
- —升級至 9.5.18 或更新版本
- —升級至 9.5.18 或更新版本
- —未列出修補版本
CVE-2024-1313 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 9.5.0, < 9.5.18, >= 10.0.0, < 10.0.13, >= 10.1.0, < 10.1.9, >= 10.2.0, < 10.2.6, >= 10.3.0, < 10.3.5
- >= 9.5.0, < 9.5.18
- from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |