编辑者(Editor)角色在通过仪表盘 API 创建仪表盘时,可以设置文件配置元数据(即 、 和 注解),因为这些字段在存储时未进行权限检查。这会导致该仪表盘被标记为“文件配置”(file-provisioned),从而使管理员无法再通过 Grafana 界面对其进行更新或删除。该漏洞的影响范围仅限于同一组织内部,且不会导致任何数据泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 12.0.0 ~ 12.0.10 | - |
|
| Grafana | Grafana Enterprise | 12.0.0 ~ 12.0.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet