{"id":"CVE-2024-1442","aliases":["BIT-grafana-2024-1442","GHSA-5mxf-42f5-j782","GO-2024-2629"],"url":"https://o3.security/vulnerability/CVE-2024-1442","summary":"User with permissions to create a data source can CRUD all data sources","details":" A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.\nDoing this will grant the user access to read, query, edit and delete all data sources within the organization.\n","published":"2024-03-07T17:45:43.993Z","modified":"2026-08-12T03:51:27.968532386Z","cvss":{"score":6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"9.5.7"},{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"10.0.12"},{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"10.1.8"},{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"10.2.5"},{"ecosystem":"Go","name":"github.com/grafana/grafana","fixedVersion":"10.3.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1442.json"},{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2024-1442/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1442"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241122-0007/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.968532386Z"}}