CVE-2024-6322 | Grafana/Grafana Enterprise up to 11.1.0/11.1.2 plugin.json ReqActions privileges assignment
A vulnerability was found in Grafana and Grafana Enterprise up to 11.1.0/11.1.2. It has been rated as problematic. This vulnerability affects unknown code of the file plugin.json. Performing manipulation of the argument ReqActions results in incorrect privilege assignment.
This vulnerability is cataloged as CVE-2024-6322. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.