Unit 42
Read post

Exposing a New BOLA Vulnerability in Grafana

A new Broken Object Level Authorization (BOLA) vulnerability has been discovered in Grafana, impacting multiple versions. This vulnerability allows low-privileged users to delete dashboard snapshots belonging to other organizations. Attackers can potentially exploit these issues to access sensitive data or compromise data integrity. Mitigations and fixes have been released.

    #data-observability#grafana#security#vulnerability
Mar 27, 2024•9m read time•From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryTable of ContentsBroken Object-Level Authorization (BOLA)GrafanaBOLA: Unauthorized Users Can Delete SnapshotsCreating Snapshots in Any Organization With Weak Key and DeleteKeyPreconditionsFixes and MitigationsDisclosure ProcessConclusion
1 Impression
Unit 42's image
Unit 42

Unit42 is a cybersecurity research team known for its analysis of cyber threats, malware, and cyber...

63 Followers

•

72 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard