Executive brief
Grafana contains an authentication bypass vulnerability where unauthenticated and authenticated users can view or delete snapshot data by accessing specific literal API paths. This occurs because the application fails to properly authorize access to snapshots with the lowest database keys, potentially leading to complete data loss.
Affected products
- Grafana Labs Grafana < 7.5.11, < 8.1.6
Timeline
- 2021-10-05: disclosed: Public disclosure via oss-security mailing list
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-08-25: advisory: NVD publication date
- 2021-10-05: patched: Fixes released in versions 8.1.6 and 7.5.11
- exploited: Reported as exploited in the wild by CISA and other sources.