Grafana Enterprise 7.2.0 introduced a mechanism which allowed users with the Editor role to bypass data source permissions for the organization’s default data source.
Side note: * Released RHEL-8.3 contains grafana-6.7.4 * Not yet release RHEL-8.4 contains grafana-7.3.6
Taus, can you please share more info, so we can start working on a reproducer and a fix ?
(In reply to Jan Kurik from comment #2) > Taus, can you please share more info, so we can start working on a > reproducer and a fix ? Jan, Are you asking about RHEL specifically? Platforms Analysis team will create trackers if needed and they may add more information there.
Yes, I was asking about grafana in RHEL. I will wait for the info from Platforms Analysis team. Thanks for the info.
Statement: Red Hat products do not ship Grafana Enterprise version, therefore are not affected by this vulnerability.
Mitigation: If you are using the Enterprise version of Grafana, you can mitigate this vulnerability by making sure that the default data source for every Grafana organization points to a data source without permissions set up.
External References: https://github.com/grafana/grafana/blob/master/CHANGELOG.md#745-2021-03-18
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-27962