Record summary

CVE-2024-11741 has a selected CVSS score of 4.3 (medium).

Description

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3,  11.2.6, 11.1.11, 11.0.11 and 10.4.15

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List11.4.0 to < 11.4.1affected
11.3.0 to < 11.3.3affected
11.2.0 to < 11.2.6affected
11.1.0 to < 11.1.11affected
10.4.0 to < 10.4.15affected

github.com/grafana/grafana

Browse Go / github.com/grafana/grafana
GitHub Advisory11.4.0affected
11.4.0 to < 11.4.1 · Fixed in 11.4.1affected
11.3.0 to < 11.3.3 · Fixed in 11.3.3affected
11.2.0 to < 11.2.6 · Fixed in 11.2.6affected
11.1.0 to < 11.1.11 · Fixed in 11.1.11affected
11.0.0 to < 11.0.11 · Fixed in 11.0.11affected
1.9.2 to < 10.4.15 · Fixed in 10.4.15affected
Before 0.0.0-20250129224826-70073427041e · Fixed in 0.0.0-20250129224826-70073427041eaffected
0.0.0 to < 1.9.2-0.20250129224826-70073427041e · Fixed in 1.9.2-0.20250129224826-70073427041eaffected

References

6