VDB
CVE-2024-6322
CVE-2024-6322
PUBLISHED
CVSS 4.400000095367432 MEDIUM
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource.
EPSS 0.30% · 22.6th percentile
Risk Scores
CVSS 3.1
4.400000095367432
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L
EPSS Score
0.30%
22.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 11.1.0 |
| Bitnami | grafana | 11.1.0 |
Timeline
- Aug 20, 2024 CVE Published
- Aug 21, 2024 EPSS Score
- Sep 11, 2024 EPSS Score
- Oct 1, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 22, 2024 EPSS Score
- Nov 11, 2024 EPSS Score
- Dec 3, 2024 EPSS Score
- Dec 24, 2024 EPSS Score
- Jan 13, 2025 EPSS Score
- Feb 3, 2025 EPSS Score
- Feb 24, 2025 EPSS Score