CVE-2024-8118
Description
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
Is your site exposed to CVE-2024-8118?
Run a free security scan — no signup, results in seconds.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2024-8118? +
How do I check if I'm vulnerable to CVE-2024-8118? +
Related Vulnerabilities
A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly …
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by …
Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges …
When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using …
When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using …
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.