Bug 2024730 (CVE-2021-41244)

Summary: CVE-2021-41244 grafana: Incorrect access control in fine-grained access control feature
Product: [Other] Security Response Reporter: Pedro Sampaio <psampaio>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: agerstmayr, amctagga, amuller, anharris, anpicker, aos-bugs, bmontgom, bniver, eparis, erooth, flucifre, gghezzo, gmeno, gparvin, grafana-maint, hvyas, jburrell, jkurik, jokerman, jramanat, jwendell, mbenjamin, mgoodwin, mhackett, nathans, nstielau, pahickey, puebele, rcernich, sostapov, spasquie, sponnaga, stcannon, twalsh, vereddy, vkumar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: grafana 8.2.4 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in grafana. When the fine-grained access control feature is enabled, and there is more than one organization in the Grafana instance, users with admin role in one organization can list, add, remove, and update users’ roles in other organizations in which they are not an admin.
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-12-02 20:39:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2024732    

Description Pedro Sampaio 2021-11-18 19:08:25 UTC
It was discovered that when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance, Grafana 8.0 introduced a mechanism which allowed users with the Organization Admin role to list, add, remove, and update users’ roles in other organizations in which they are not an admin. 

References:

https://github.com/grafana/grafana/security/advisories/GHSA-mpwp-42x6-4wmx
https://grafana.com/blog/2021/11/15/grafana-8.2.4-released-with-security-fixes/
http://www.openwall.com/lists/oss-security/2021/11/15/1

Comment 2 Product Security DevOps Team 2021-12-02 20:39:32 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-41244