In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
https://access.redhat.com/security/cve/CVE-2024-8118 states "will not fix" yet this BZ is still open. Is there a chance it'll be fixed, either by a version bump or backport?