Grafana Databricks Datasource Plugin OAuth Passthrough Vulnerability Leading to Unauthorized Data Access
Vulnerability
A vulnerability exists in the Grafana Databricks Datasource Plugin versions 1.6.0 prior to 1.12.0, when OAuth passthrough is enabled. In scenarios where multiple users access the same datasource simultaneously on a single Grafana instance, the wrong user identifier may be used. This can result in unauthorized information being returned to users.
Impact
Exploitation of this vulnerability could lead to unauthorized access to information, allowing users to view data for which they do not have permission.
Remediation
Users can update to Grafana Databricks Datasource Plugin version 1.12.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
