On Grafana instances using an external authentication service and having the editorsCanAdmin feature enabled, Grafana Enterprise 6.1.0 introduced a mechanism which allows any authenticated user to add external groups to any existing team, without having to be an Admin of the team. This can be used to grant a user team permissions that the user isn’t supposed to have. This vulnerability allows users to bypass access control restrictions. The vulnerability can only be triggered if you have defined at least one team in Grafana, even if that team is unused.
Statement: Red Hat products do not ship Grafana Enterprise version, therefore they are not affected by this vulnerability.
External References: https://github.com/grafana/grafana/blob/master/CHANGELOG.md#745-2021-03-18
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-28147