Summary
Security updates have been released to address a critical vulnerability in Grafana, a popular web application for interactive data visualization and analysis.
Risk
Vulnerability impact estimate on the community: HIGH/ORANGE (66.53/100)1.
Type
- Remote Code Execution
- Arbitrary File Write/Read
Affected products and versions
Grafana
- 11.0.x, versions prior to 11.0.5+security-01
- 11.1.x, versions prior to 11.1.6+security-01
- 11.2.x, versions prior to 11.2.1+security-01
Mitigation actions
In line with vendor statements, it is recommended to update vulnerable products following the instructions in the security bulletin reported in the References section.
Unique Vulnerability Identifiers
References
https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264
1This estimate is made taking into account several parameters, including: CVSS, availability of patches/workarounds and PoC, diffusion of the affected software/devices in the reference community.