Home / Companies / Grafana Labs / Blog / Post Details
Content Deep Dive

Grafana security release: New versions of Grafana with a medium severity security fix for CVE-2023-4822

Blog post from Grafana Labs

Post Details
Company
Date Published
Author
Ieva Vasiļjeva
Word Count
665
Company Posts That Month
26
Language
English
Hacker News Points
-
Post removed?
No
Summary

Grafana Labs has released new versions, 10.1.5, 10.0.9, 9.5.13, and 9.4.17, to address a medium-severity security vulnerability, CVE-2023-4822, in the role-based access control (RBAC) system of Grafana Enterprise. This vulnerability allows organization administrators to alter permissions across different organizations, posing a risk in instances running multiple organizations, though Grafana Cloud instances are unaffected. The issue, with a CVSS score of 6.7, was identified in versions 8.0.0 to 10.1.4, and users are advised to upgrade to the patched versions or limit administrator privileges to trusted individuals if immediate upgrading is not feasible. The timeline reveals the vulnerability's discovery and patching process, culminating in a public release on October 12, 2023. Grafana Labs encourages reporting of security vulnerabilities via their dedicated page, urging discretion until a public announcement is made.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.