Grafana Incorrect Authorization Vulnerability - CVE-2021-28146 - Vulnerability Database

Grafana Incorrect Authorization Vulnerability - CVE-2021-28146

Medium
Reference: CVE-2021-28146
Title: Grafana Incorrect Authorization Vulnerability
Overview:

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn39t supposed to have.