CVE-2024-1313: Grafana: Users outside an organization can delete a snapshot with its key
(updated )
The DELETE /api/snapshots/{key} endpoint allows any Grafana user to delete snapshots if the user is NOT in the organization of the snapshot
References
Detect and mitigate CVE-2024-1313 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →