BIT-grafana-2023-2183

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2023-2183.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-grafana-2023-2183
Aliases
Published
2024-03-06T10:53:35.301Z
Modified
2025-04-03T14:40:37.652Z
Summary
[none]
Details

Grafana is an open-source platform for monitoring and observability.

The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API does not check access to this function.

This might enable malicious users to abuse the functionality by sending multiple alert messages to e-mail and Slack, spamming users, prepare Phishing attack or block SMTP server.

Users may upgrade to version 9.5.3, 9.4.12, 9.3.15, 9.2.19 and 8.5.26 to receive a fix.

Database specific
{
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.5.26
Introduced
9.0.0
Fixed
9.2.19
Introduced
9.3.0
Fixed
9.3.15
Introduced
9.4.0
Fixed
9.4.12
Introduced
9.5.0
Fixed
9.5.3

Database specific

source

"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2023-2183.json"