Race condition In grafana
Description
A flaw was found in Grafana. This vulnerability, known as a time-of-create-to-time-of-use (TOCTOU) issue, allows an attacker to delete a data source without proper authorization. For this to occur, the attacker must have previously managed the data source, and it must be recreated with the same unique identifier (UID) within a 30-second window on the same Grafana server. The consequence is the unauthorized deletion of a data source, which can lead to a denial of service for that specific resource.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3.