VDB
CVE-2024-8118
CVE-2024-8118
PUBLISHED
CVSS 5.099999904632568 MEDIUM
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
EPSS 0.58% · 45.4th percentile
Risk Scores
CVSS 4.0
5.099999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
0.58%
45.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | grafana | 8.5.0, 11.0.0 |
| Bitnami | grafana | 11.0.0, 8.5.0 |
Timeline
- Sep 26, 2024 CVE Published
- Sep 26, 2024 PoC Published
- Sep 27, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 16, 2024 EPSS Score
- Nov 5, 2024 EPSS Score
- Nov 24, 2024 EPSS Score
- Dec 15, 2024 EPSS Score
- Jan 3, 2025 EPSS Score
- Jan 22, 2025 EPSS Score
- Feb 11, 2025 EPSS Score
- Feb 13, 2025 CVE Updated