All verified exploits

CVE-2024-1442 Wildcard UID Privilege Escalation

Deterministic medium Grafana Added cve-verified-cve-2024-1442

Confirms that Grafana's data source proxy accepts wildcard UID (*) in the URL path, allowing any authenticated viewer to query all configured data sources regardless of permissions. Affects Grafana 8.x through 10.3.3.

Is your app exploitable through CVE-2024-1442?

Scan your domain free