Information disclosure in Grafana - CVE-2024-11741

 

Information disclosure in Grafana - CVE-2024-11741

Published: February 3, 2025


Vulnerability identifier: #VU103503
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11741
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application within the Grafana Alerting VictorOps integration. A remote user can gain unauthorized access to sensitive information on the system.


Affected software

Grafana
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Manager Client Tools for SLE
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Package Hub 15
openSUSE Leap
grafana
grafana-debuginfo

How to mitigate CVE-2024-11741

Install updates from vendor's website.

Grafana - addressed in versions 10.4.15, 11.0.11, 11.1.11, 11.2.6, 11.3.3, 11.4.1, 11.5.0
grafana - addressed in versions 10.4.15-1.71.1, 10.4.15-150000.1.71.1, 10.4.15-150200.3.64.1
grafana-debuginfo - addressed in versions 10.4.15-150000.1.71.1, 10.4.15-150200.3.64.1

External References

Related Security Bulletins