Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-cli-rhel9:v2.12.0-17", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-cluster-permission-rhel9:v2.12.0-13", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-governance-policy-addon-controller-rhel9:v2.12.0-27", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-governance-policy-framework-addon-rhel9:v2.12.0-20", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-grafana-rhel9:v2.12.0-17", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-multicluster-observability-addon-rhel9:v2.12.0-20", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-must-gather-rhel9:v2.12.0-35", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-operator-bundle:v2.12.0-114", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-prometheus-config-reloader-rhel9:v2.12.0-16", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-prometheus-rhel9:v2.12.0-16", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-search-indexer-rhel9:v2.12.0-12", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-search-v2-api-rhel9:v2.12.0-15", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-search-v2-rhel9:v2.12.0-13", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-siteconfig-rhel9:v2.12.0-24", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/acm-volsync-addon-controller-rhel9:v2.12.0-22", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/cert-policy-controller-rhel9:v2.12.0-22", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/cluster-backup-rhel9-operator:v2.12.0-37", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/config-policy-controller-rhel9:v2.12.0-31", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/console-rhel9:v2.12.0-68", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/endpoint-monitoring-rhel9-operator:v2.12.0-39", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/governance-policy-propagator-rhel9:v2.12.0-29", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/grafana-dashboard-loader-rhel9:v2.12.0-39", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/insights-client-rhel9:v2.12.0-18", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/insights-metrics-rhel9:v2.12.0-18", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/klusterlet-addon-controller-rhel9:v2.12.0-12", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/kube-rbac-proxy-rhel9:v2.12.0-13", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/kube-state-metrics-rhel9:v2.12.0-17", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/memcached-exporter-rhel9:v2.12.0-10", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/memcached-rhel9:v2.12.0-7", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/metrics-collector-rhel9:v2.12.0-39", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/multicloud-integrations-rhel9:v2.12.0-12", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/multiclusterhub-rhel9:v2.12.0-51", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/multicluster-observability-rhel9-operator:v2.12.0-39", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/multicluster-operators-application-rhel9:v2.12.0-14", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/multicluster-operators-channel-rhel9:v2.12.0-12", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/multicluster-operators-subscription-rhel9:v2.12.0-24", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/node-exporter-rhel9:v2.12.0-10", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/observatorium-rhel9:v2.12.0-16", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/observatorium-rhel9-operator:v2.12.0-17", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/prometheus-alertmanager-rhel9:v2.12.0-12", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/prometheus-rhel9:v2.12.0-14", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/rbac-query-proxy-rhel9:v2.12.0-39", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/search-collector-rhel9:v2.12.0-21", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/submariner-addon-rhel9:v2.12.0-24", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/thanos-receive-controller-rhel9:v2.12.0-13", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:8974", "cpe": "cpe:/a:redhat:acm:2.12::el9", "package": "rhacm2/thanos-rhel9:v2.12.0-18", "product_name": "Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9", "release_date": "2024-11-06T00:00:00Z"}, {"advisory": "RHSA-2024:2633", "cpe": "cpe:/a:redhat:ceph_storage:6.1::el9", "package": "rhceph/rhceph-6-dashboard-rhel9:6-90", "product_name": "Red Hat Ceph Storage 6.1", "release_date": "2024-05-01T00:00:00Z"}], "bugzilla": {"description": "grafana: Improper priviledge managent for users with data source permissions", "id": "2268486", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2268486"}, "csaw": false, "cvss3": {"cvss3_base_score": "6.0", "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L", "status": "verified"}, "cwe": "CWE-269", "details": ["A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.\nDoing this will grant the user access to read, query, edit and delete all data sources within the organization.", "A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized access to read, query, edit, and delete all data sources within the organization. Such unrestricted access can lead to data breaches, manipulation, privacy violations, and compliance issues, emphasizing the critical importance of implementing stringent access controls and monitoring API usage."], "mitigation": {"lang": "en:us", "value": "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."}, "name": "CVE-2024-1442", "package_state": [{"cpe": "cpe:/a:redhat:ceph_storage:4", "fix_state": "Affected", "package_name": "rhceph/rhceph-4-dashboard-rhel8", "product_name": "Red Hat Ceph Storage 4"}, {"cpe": "cpe:/a:redhat:ceph_storage:5", "fix_state": "Affected", "package_name": "rhceph/rhceph-5-dashboard-rhel8", "product_name": "Red Hat Ceph Storage 5"}, {"cpe": "cpe:/a:redhat:ceph_storage:7", "fix_state": "Affected", "package_name": "rhceph/grafana-rhel9", "product_name": "Red Hat Ceph Storage 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "grafana", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Not affected", "package_name": "grafana", "product_name": "Red Hat Enterprise Linux 9"}, {"cpe": "cpe:/a:redhat:openshift:3.11", "fix_state": "Not affected", "package_name": "openshift3/grafana", "product_name": "Red Hat OpenShift Container Platform 3.11"}, {"cpe": "cpe:/a:redhat:storage:3", "fix_state": "Affected", "package_name": "grafana", "product_name": "Red Hat Storage 3"}], "public_date": "2024-03-07T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2024-1442\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-1442\nhttps://github.com/advisories/GHSA-5mxf-42f5-j782"], "statement": "The issue of allowing users to set the UID to '*' via the Grafana API presents a moderate severity concern due to its potential impact on data integrity and security within the organization's Grafana instance. While the risk of unauthorized access and data manipulation is significant, its severity is tempered by the prerequisite of having permission to create a data source in the first place. However, once exploited, this vulnerability enables an attacker to bypass access controls and gain unfettered access to all data sources, allowing them to read, query, edit, and delete sensitive information.", "threat_severity": "Moderate"}