Description
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode
Remediation
References
Related Vulnerabilities
WordPress Plugin Properties and Agents-Real Estate Manager Cross-Site Scripting (6.7.1)
Moodle Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2023-28334)
Oracle JRE CVE-2013-5782 Vulnerability (CVE-2013-5782)
WordPress Plugin Gallery-Flagallery Photo Portfolio Cross-Site Scripting (2.70)