Exposing a New BOLA Vulnerability in Grafana
ID: 6f1f8390-f821-5e41-9b74-71a31e189dc7
STIX ID: report--6f1f8390-f821-5e41-9b74-71a31e189dc7
Feed Name: Palo Alto Networks Unit 42
**CVE-2024-1313 (Grafana BOLA)**: Unit 42 discovered a Broken Object-Level Authorization flaw in Grafana dashboards that allows low-privileged or unauthenticated users to delete snapshots across organizations if they know or can guess the snapshot key; additionally, the POST /api/snapshots endpoint permits user-supplied weak keys, enabling brute-force discovery or DoS via large snapshots. Affected versions include 9.5.0 before 9.5.18, 10.0.0 before 10.0.13, 10.1.0 before 10.1.9, 10.2.0 before 10.2.6, and 10.3.0 before 10.3.5; Grafana published fixes and Prisma Cloud/WAAS rules are provided as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
