| id: GO-2024-2697 |
| modules: |
| - module: github.com/grafana/grafana |
| non_go_versions: |
| - introduced: 9.5.0 |
| - fixed: 9.5.18 |
| - introduced: 10.0.0 |
| - fixed: 10.0.13 |
| - introduced: 10.1.0 |
| - fixed: 10.1.9 |
| - introduced: 10.2.0 |
| - fixed: 10.2.6 |
| - introduced: 10.3.0 |
| - fixed: 10.3.5 |
| vulnerable_at: 5.4.5+incompatible |
| summary: 'Grafana: Users outside an organization can delete a snapshot with its key in github.com/grafana/grafana' |
| cves: |
| - CVE-2024-1313 |
| ghsas: |
| - GHSA-67rv-qpw2-6qrr |
| unknown_aliases: |
| - BIT-grafana-2024-1313 |
| references: |
| - advisory: https://github.com/grafana/bugbounty/security/advisories/GHSA-67rv-qpw2-6qrr |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-1313 |
| - web: https://grafana.com/security/security-advisories/cve-2024-1313 |
| source: |
| id: GHSA-67rv-qpw2-6qrr |
| created: 2024-06-04T15:31:16.41185-04:00 |
| review_status: UNREVIEWED |