CVE-2021-41244

Cross organization admin control in Grafana

Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations. Grafana 8.0 introduced a mechanism which allowed users with the Organization Admin role to list, add, remove, and update users’ roles in other organizations in which they are not an admin. With fine-grained access control enabled, organization admins can list, add, remove and update users' roles in another organization, where they do not have organization admin role. All installations between v8.0 and v8.2.3 that have fine-grained access control beta enabled and more than one organization should be upgraded as soon as possible. If you cannot upgrade, you should turn off the fine-grained access control using a feature flag.


We have discovered 9 live websites that are affected by CVE-2021-41244.

Run a Free Instant Scan




Affected Software

Product  Grafana
Category Analytics
Vulnerable Domains9 live websites (1.16% of Grafana install base)
Vulnerable Versions
  • from 8 through 8.2.4
Vulnerable Versions Count2 versions ( 2.27% of all versions)


Common Weakness Enumeration

CWE-610 Externally Controlled Reference to a Resource in Another Sphere



Details

  • Published - Nov 16, 2021
  • Updated - Aug 4, 2024

Website Distribution by Country

Number of websites using CVE-2021-41244
United States4 websites



Germany2 websites
Brazil1 websites
Finland1 websites
Indonesia1 websites

Website Distribution by TLD

Number of websites using CVE-2021-41244
.com3 websites
.com.br1 websites
.fi1 websites
.org1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-41244

Top websites that are affected by CVE-2021-41244. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States***,***
*******.***********.com United States**,***,***
*******.*****.org Indonesia**,***,***
****.*********.com United States**,***,***
****.***********.no United States**,***,***
*************.******.***.br Brazil**,***,***
******.********.gr Germany**,***,***
********.tech Germany***,***,***
************.fi Finland***,***,***
See full domain list

FAQ

CVE-2021-41244 is Externally Controlled Reference to a Resource in Another Sphere in Grafana
A total of 9 websites have been identified as vulnerable to CVE-2021-41244, based on global website indexing conducted by WebTechSurvey.
The Grafana is affected by the CVE-2021-41244 vulnerability.
Grafana versions up to 8.2.4 are vulnerable to CVE-2021-41244.
CVE-2021-41244 is resolved in version 8.2.4 of Grafana.