Back

MEDIUM

grafana: missing access control allows test alerts by underprivileged user

Published Jun 6, 2023

Description

Grafana is an open-source platform for monitoring and observability.

The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API does not check access to this function.

This might enable malicious users to abuse the functionality by sending multiple alert messages to e-mail and Slack, spamming users, prepare Phishing attack or block SMTP server.

Users may upgrade to version 9.5.3, 9.4.12, 9.3.15, 9.2.19 and 8.5.26 to receive a fix.

Affected products

Remediation

Red Hat statement

OpenShift ServiceMesh (OSSM) has switched to using upstream rhel rpms for grafana, and is no longer maintaining the servicemesh-grafana package. Hence, it is marked as affected/won'tfix.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GRAFANA
Published Jun 6, 2023
Updated Feb 13, 2025
Reserved Apr 19, 2023
CISA Vulnrichment
Updated Jan 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 6, 2023
ENISA EUVD
Assigner GRAFANA
Published Jun 6, 2023
Updated Feb 13, 2025
Exploited since n/a
EUVD-2023-1778 GHSA-CVM3-PP2J-CHR3