以下是该漏洞描述信息的中文翻译: 摘要 拥有创建或编辑文件夹中告警规则权限的组织用户,可以查询其不具备 (数据源查询)权限的数据源。攻击者将客户端可控的查询字段 设置为 ,同时保留真实数据源的 UID。 告警规则授权路径将查询视为服务器端表达式,从而绕过了数据源权限的强制执行。随后,评估器会根据由 标识的真实数据源解析并执行该查询。 影响 此绕过漏洞可让未被授权直接查询特定数据源的低权限用户,访问通过 Grafana 配置的数据源凭据可获取的数据。保密性影响为高。 完整性影响为低,因为部分数据源后端及配置的凭据可能
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana Enterprise | 8.4.0< 12.3.11 |
affected |
12.4.0< 12.4.9 |
affected | ||
13.0.0< 13.0.7 |
affected | ||
13.1.0< 13.1.4 |
affected | ||
| Grafana | Grafana OSS | 8.4.0< 12.3.11 |
affected |
12.4.0< 12.4.9 |
affected | ||
13.0.0< 13.0.7 |
affected | ||
13.1.0< 13.1.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 8.4.0 ~ 12.3.11 | - |
|
| Grafana | Grafana Enterprise | 8.4.0 ~ 12.3.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet