CVE-2024-9476

CVSS 3.1 Score 0 of 10 (low)

Details

Published Nov 13, 2024
Updated: Nov 15, 2024
CWE ID 266

Summary

CVE-2024-9476 is a newly discovered vulnerability in Grafana Labs' Grafana Open Source and Enterprise versions. It enables Privilege Escalation, allowing users with access to an affected Grafana instance to gain unauthorized access to resources from other organizations using the same instance via the Grafana Cloud Migration Assistant. This issue is significant as it can potentially compromise the security of multiple organizations sharing the same Grafana instance, and only affects those utilizing the Organizations feature to isolate resources.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share