Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.127205
Category:Web application abuses
Title:Grafana 8.5.0 < 8.5.13, 9.0.0 < 9.0.9, 9.1.0 < 9.1.6 Privilege escalation Vulnerability (GHSA-p978-56hq-r492)
Summary:Grafana is prone to a privilege escalation Vulnerability.
Description:Summary:
Grafana is prone to a privilege escalation Vulnerability.

Vulnerability Impact:
The vulnerability impacts Grafana instances where RBAC was
disabled and enabled afterwards, as the migrations which are translating legacy folder
permissions to RBAC permissions do not account for the scenario where the only user permission in
the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them
to edit and view folders accordingly.

Affected Software/OS:
Grafana version 8.5.0 prior to 8.5.13, version 9.0.0 prior to
9.0.9 and version 9.1.0 prior to 9.1.6.

Solution:
Update to version 8.5.13, 9.0.9, 9.1.6 or later.

CVSS Score:
4.7

CVSS Vector:
AV:N/AC:L/Au:M/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2022-36062
https://github.com/grafana/grafana/security/advisories/GHSA-p978-56hq-r492
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.