Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-736h-475m-xhjc

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path.

Only instances with the sqlExpressions feature toggle enabled are vulnerable.

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path.

Only instances with the sqlExpressions feature toggle enabled are vulnerable.

EPSS

Процентиль: 23%
0.00079
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.1
redhat
4 дня назад

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 9.1
nvd
4 дня назад

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 9.1
debian
4 дня назад

A chained attack via SQL Expressions and a Grafana Enterprise plugin c ...

EPSS

Процентиль: 23%
0.00079
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94