Grafana 11.0.0

CPE Details

Grafana 11.0.0
11.0.0
2025-01-15
18h15 +00:00
2025-01-15
18h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:grafana:grafana:11.0.0:*:*:*:*:*:*:*

Informations

Vendor

grafana

Product

grafana

Version

11.0.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-9264 2024-10-18 03h20 +00:00 The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.
9.4
Critical