A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization. References: https://grafana.com/security/security-advisories/cve-2024-1442/
Created grafana tracking bugs for this issue: Affects: fedora-all [bug 2268487]
This issue has been addressed in the following products: Red Hat Ceph Storage 6.1 Via RHSA-2024:2633 https://access.redhat.com/errata/RHSA-2024:2633