{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-9476",
        "assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
        "state": "PUBLISHED",
        "assignerShortName": "GRAFANA",
        "dateReserved": "2024-10-03T12:58:42.842Z",
        "datePublished": "2024-11-13T16:30:54.581Z",
        "dateUpdated": "2025-11-23T15:33:38.284Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Grafana OSS and Enterprise",
                    "vendor": "Grafana Labs",
                    "versions": [
                        {
                            "lessThan": "11.3.0+security-01",
                            "status": "affected",
                            "version": "11.3.0",
                            "versionType": "semver"
                        },
                        {
                            "lessThan": "11.2.3+security-01",
                            "status": "affected",
                            "version": "11.2.0",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "configurations": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "The feature toggle&nbsp;<tt><code>onPremToCloudMigrations</code></tt> must be enabled for this vulnerability to be activated. <br>See <a target=\"_blank\" rel=\"nofollow\" href=\"https://grafana.com/docs/grafana-cloud/account-management/migration-guide/\">https://grafana.com/docs/grafana-cloud/account-management/migration-guide/</a> for more details<br>"
                        }
                    ],
                    "value": "The feature toggle onPremToCloudMigrations must be enabled for this vulnerability to be activated. \nSee  https://grafana.com/docs/grafana-cloud/account-management/migration-guide/  for more details"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.<div><div>This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance.</div></div>"
                        }
                    ],
                    "value": "A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate resources on their Grafana instance."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-233",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-233 Privilege Escalation"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "LOCAL",
                        "baseScore": 5.1,
                        "baseSeverity": "MEDIUM",
                        "privilegesRequired": "HIGH",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "ACTIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "vulnIntegrityImpact": "NONE",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-266",
                            "description": "CWE-266",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
                "shortName": "GRAFANA",
                "dateUpdated": "2025-11-23T15:33:38.284Z"
            },
            "references": [
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://grafana.com/security/security-advisories/cve-2024-9476/"
                },
                {
                    "url": "https://grafana.com/blog/2024/11/12/grafana-security-release-medium-severity-security-fix-for-cve-2024-9476/"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Privilege escalation vulnerability for Organizations in Grafana",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2024-11-14T15:54:30.628886Z",
                                "id": "CVE-2024-9476",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-11-21T16:13:24.654Z"
                }
            }
        ]
    }
}