Description
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.
Remediation
References
Related Vulnerabilities
MySQL CVE-2021-35628 Vulnerability (CVE-2021-35628)
XWiki Improper Restriction of XML External Entity Reference Vulnerability (CVE-2023-27480)
WordPress Plugin Contest Gallery-Photo Contest for WordPress Cross-Site Request Forgery (10.4.1.1)
Envoy Proxy Memory Allocation with Excessive Size Value Vulnerability (CVE-2026-49975)
WordPress Plugin String locator PHAR Deserialization (2.5.0)