Race condition In grafana

Description

A flaw was found in Grafana. This vulnerability, known as a time-of-create-to-time-of-use (TOCTOU) issue, allows an attacker to delete a data source without proper authorization. For this to occur, the attacker must have previously managed the data source, and it must be recreated with the same unique identifier (UID) within a 30-second window on the same Grafana server. The consequence is the unauthorized deletion of a data source, which can lead to a denial of service for that specific resource.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package