Total vulnerabilities in the database
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.
Software | From | Fixed in |
---|---|---|
![]() |
8.5.0 | 9.5.7 |
![]() |
10.0.0 | 10.0.12 |
![]() |
10.1.0 | 10.1.8 |
![]() |
10.2.0 | 10.2.5 |
![]() |
10.3.0 | 10.3.4 |
grafana / grafana | 10.0.0 | 10.0.12 |
grafana / grafana | 10.1.0 | 10.1.8 |
grafana / grafana | 10.2.0 | 10.2.5 |
grafana / grafana | 10.3.0 | 10.3.4 |
grafana / grafana | 8.5.0 | 9.5.7 |