CRITICAL9.9
GHSA-q99m-qcv4-fpm7
Grafana Command Injection And Local File Inclusion Via Sql Expressions
Quick fix
GHSA-q99m-qcv4-fpm7 — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v11.0.6+security-01Details
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
11.0.0Fixed in: 11.0.6+security-01Fix
go get github.com/grafana/grafana@v11.0.6+security-01Go/github.com/grafana/grafana
Introduced in:
11.1.0Fixed in: 11.1.7+security-01Fix
go get github.com/grafana/grafana@v11.1.7+security-01Go/github.com/grafana/grafana
Introduced in:
11.2.0Fixed in: 11.2.2+security-01Fix
go get github.com/grafana/grafana@v11.2.2+security-01References
- https://nvd.nist.gov/vuln/detail/CVE-2024-9264[ADVISORY]
- https://github.com/grafana/grafana/pull/81666[WEB]
- https://github.com/grafana/grafana[PACKAGE]
- https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264[WEB]
- https://grafana.com/security/security-advisories/cve-2024-9264[WEB]
- https://security.netapp.com/advisory/ntap-20250314-0007[WEB]