Unauthorized access to screen In grafana
Description
A flaw was found in Grafana's alerting system. Users with editor permissions, specifically those able to write or test alert notifications, can modify contact points created by other users. By changing the endpoint URL to a controlled server and triggering the test functionality, an attacker can capture and extract sensitive secure settings, such as authentication credentials for third-party services. This vulnerability leads to unauthorized access and potential compromise of external integrations.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Aliases
1. 2. 3.