• pageflight@piefed.social
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 days ago

    To save a click:

    in its Enterprise product that can be exploited to treat new users as administrators or for privilege escalation.

    The issue is only exploitable when SCIM (System for Cross-domain Identity Management) provisioning is enabled and configured.

    So self-hosted Grafana / locally managed users is unaffected.