Описание
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
A flaw was found in Grafana. A remote attacker with authenticated access to a SQL datasource can exploit a vulnerability in the $__timeGroup macro. By sending specially crafted queries, an attacker can cause an Out of Memory (OOM) error, leading to the Grafana server crashing and resulting in a Denial of Service (DoS). This can disrupt the availability of the Grafana instance.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Hardened Images | hi/grafana | Not affected | ||
| Red Hat Hardened Images | grafana13-1-main-13.1.6-0.1.hum1 | Fixed | RHSA-2026:68767 | 17.09.2026 |
| Red Hat Hardened Images | grafana13-2-main-13.2.1-0.5.hum1 | Fixed | RHSA-2026:68778 | 17.09.2026 |
| Red Hat Hardened Images | grafana12-4-main-12.4.10-0.6.hum1 | Fixed | RHSA-2026:68821 | 18.09.2026 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
Using the $__timeGroup macro, one can achieve an OOM by overloading th ...
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
Уязвимость встроенного макроса $__timeGroup платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю вызвать отказ в обслуживании
6.5 Medium
CVSS3