« Volver al listado

CVE-2024-1442

Estado: AnalizadaAlta (8.8)—

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1442",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1442",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-26T14:35:40.672183Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@grafana.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@grafana.com",
      "affectedData": [
        {
          "vendor": "Grafana",
          "product": "Grafana",
          "versions": [
            {
              "status": "affected",
              "version": "8.5.0",
              "lessThan": "9.5.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.0.0",
              "lessThan": "10.0.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.1.0",
              "lessThan": "10.1.8",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.2.0",
              "lessThan": "10.2.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.3.0",
              "lessThan": "10.3.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-03-07T18:15:46.590",
  "references": [
    {
      "url": "https://grafana.com/security/security-advisories/cve-2024-1442/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@grafana.com"
    },
    {
      "url": "https://grafana.com/security/security-advisories/cve-2024-1442/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20241122-0007/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@grafana.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": " A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.\nDoing this will grant the user access to read, query, edit and delete all data sources within the organization.\n"
    },
    {
      "lang": "es",
      "value": "Un usuario con permisos para crear una fuente de datos puede usar Grafana API para crear una fuente de datos con UID configurado en *. Hacer esto le otorgará al usuario acceso para leer, consultar, editar y eliminar todas las fuentes de datos dentro de la organización."
    }
  ],
  "lastModified": "2026-06-17T07:04:15.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "256F06F9-C861-48F9-8317-A0F0133C0FBE",
              "versionEndExcluding": "9.5.7",
              "versionStartIncluding": "8.5.0"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "768ED1D5-DD09-4D2B-AD74-F5D1A03DF8D7",
              "versionEndExcluding": "10.0.12",
              "versionStartIncluding": "10.0.0"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "642B089C-E5B7-4AD4-B477-2579A8A1AB23",
              "versionEndExcluding": "10.1.8",
              "versionStartIncluding": "10.1.0"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF474EF5-B4C2-4CEF-86AD-55A116C9E15F",
              "versionEndExcluding": "10.2.5",
              "versionStartIncluding": "10.2.0"
            },
            {
              "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4854C70-56B3-49ED-BF70-28673BD4E2D7",
              "versionEndExcluding": "10.3.4",
              "versionStartIncluding": "10.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@grafana.com"
}