A new Broken Object Level Authorization (BOLA) vulnerability has been discovered in Grafana, impacting multiple versions. This vulnerability allows low-privileged users to delete dashboard snapshots belonging to other organizations. Attackers can potentially exploit these issues to access sensitive data or compromise data integrity. Mitigations and fixes have been released.

9m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryTable of ContentsBroken Object-Level Authorization (BOLA)GrafanaBOLA: Unauthorized Users Can Delete SnapshotsCreating Snapshots in Any Organization With Weak Key and DeleteKeyPreconditionsFixes and MitigationsDisclosure ProcessConclusion

Sort: