VDB

CVE-2024-8118

CVE-2024-8118 PUBLISHED CVSS 5.099999904632568 MEDIUM

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

EPSS 0.58% · 45.4th percentile

Risk Scores

CVSS 4.0
5.099999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
0.58%
45.4th percentile

Affected Products

VendorProductVersions
Bitnamigrafana8.5.0, 11.0.0
Bitnamigrafana11.0.0, 8.5.0

Timeline

  • Sep 26, 2024 CVE Published
  • Sep 26, 2024 PoC Published
  • Sep 27, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Oct 16, 2024 EPSS Score
  • Nov 5, 2024 EPSS Score
  • Nov 24, 2024 EPSS Score
  • Dec 15, 2024 EPSS Score
  • Jan 3, 2025 EPSS Score
  • Jan 22, 2025 EPSS Score
  • Feb 11, 2025 EPSS Score
  • Feb 13, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›