VDB
Sign up
CRITICAL9.9

GHSA-q99m-qcv4-fpm7

Grafana Command Injection And Local File Inclusion Via Sql Expressions

Quick fix

GHSA-q99m-qcv4-fpm7 — github.com/grafana/grafana: upgrade to the fixed version with the command below.

go get github.com/grafana/grafana@v11.0.6+security-01

Details

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/grafana/grafana
Introduced in: 11.0.0Fixed in: 11.0.6+security-01
Fixgo get github.com/grafana/grafana@v11.0.6+security-01
Go/github.com/grafana/grafana
Introduced in: 11.1.0Fixed in: 11.1.7+security-01
Fixgo get github.com/grafana/grafana@v11.1.7+security-01
Go/github.com/grafana/grafana
Introduced in: 11.2.0Fixed in: 11.2.2+security-01
Fixgo get github.com/grafana/grafana@v11.2.2+security-01

References