Vulnerabilities
Vulnerable Software
Grafana:  >> Grafana  >> 11.0.0  Security Vulnerabilities
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.
CVSS Score
9.9
EPSS Score
0.925
Published
2024-10-18


Contact Us

Shodan ® - All rights reserved