MEDIUM4.3
GHSA-wxcc-2f3q-4h58
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Quick fix
GHSA-wxcc-2f3q-4h58 — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v11.4.1Details
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
11.4.0Fixed in: 11.4.1Fix
go get github.com/grafana/grafana@v11.4.1Go/github.com/grafana/grafana
Introduced in:
11.3.0Fixed in: 11.3.3Fix
go get github.com/grafana/grafana@v11.3.3Go/github.com/grafana/grafana
Introduced in:
11.2.0Fixed in: 11.2.6Fix
go get github.com/grafana/grafana@v11.2.6Go/github.com/grafana/grafana
Introduced in:
11.1.0Fixed in: 11.1.11Fix
go get github.com/grafana/grafana@v11.1.11Go/github.com/grafana/grafana
Introduced in:
11.0.0Fixed in: 11.0.11Fix
go get github.com/grafana/grafana@v11.0.11Go/github.com/grafana/grafana
Introduced in:
1.9.2Fixed in: 10.4.15Fix
go get github.com/grafana/grafana@v10.4.15Go/github.com/grafana/grafana
Introduced in:
0Fixed in: 0.0.0-20250129224826-70073427041eFix
go get github.com/grafana/grafana@v0.0.0-20250129224826-70073427041eGo/github.com/grafana/grafana
Introduced in:
0.0.0Fixed in: 1.9.2-0.20250129224826-70073427041eFix
go get github.com/grafana/grafana@v1.9.2-0.20250129224826-70073427041eReferences
- https://nvd.nist.gov/vuln/detail/CVE-2024-11741[ADVISORY]
- https://github.com/grafana/grafana/commit/70073427041e15c353e0d467b714527584765aea[WEB]
- https://github.com/grafana/grafana[PACKAGE]
- https://grafana.com/security/security-advisories/cve-2024-11741[WEB]
- https://pkg.go.dev/vuln/GO-2025-3438[WEB]
- https://security.netapp.com/advisory/ntap-20250509-0006[WEB]