Company
Date Published
Author
Vardan Torosyan
Word count
347
Language
English
Hacker News points
None

Summary

Grafana 8.2.4 has been released to address a security vulnerability affecting versions 8.0.0 through 8.2.3, specifically impacting instances where the fine-grained access control beta is enabled and there is more than one organization. Discovered during an internal audit, this vulnerability allows users with the Organization Admin role to manage roles across organizations where they are not admins. Users with affected installations should upgrade immediately or disable the fine-grained access control feature to mitigate the risk. Notably, Grafana Cloud instances are unaffected by this issue. For reporting security vulnerabilities, Grafana Labs provides a dedicated email address and encourages the use of encrypted communication. Additionally, Grafana maintains a blog category for security announcements, offering summaries and details on patch remediations and mitigations.