{"id":"BIT-grafana-2024-1442","summary":"User with permissions to create a data source can CRUD all data sources","details":"A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.\nDoing this will grant the user access to read, query, edit and delete all data sources within the organization.","aliases":["CVE-2024-1442","GHSA-5mxf-42f5-j782","GO-2024-2629"],"modified":"2026-09-08T08:47:50.884438956Z","published":"2024-03-12T08:24:28.608Z","database_specific":{"cpes":["cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*","cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*"],"severity":"High"},"references":[{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2024-1442/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241122-0007/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1442"}],"affected":[{"package":{"name":"grafana","ecosystem":"Bitnami","purl":"pkg:bitnami/grafana"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.5.0"},{"fixed":"9.5.7"},{"introduced":"10.0.0"},{"fixed":"10.0.12"},{"introduced":"10.1.0"},{"fixed":"10.1.8"},{"introduced":"10.2.0"},{"fixed":"10.2.5"},{"introduced":"10.3.0"},{"fixed":"10.3.4"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2024-1442.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}