Fedora Account System
Red Hat Associate
Red Hat Customer
An authorization bypass in Grafana’s data source proxy API allows users to gain unauthorized access to data by inserting an additional slash (/) in the request path. This flaw affects endpoints in Alertmanager and certain Prometheus-based data sources that rely on path-specific permissions. The vulnerability impacts instances that are running Grafana >= 10.4.0