github.com
https://github.com/grafana/grafana CVE-2024-11741
MEDIUM
Grafana Alerting VictorOps integration could be exposed to users with Viewer permission
Record summary
CVE-2024-11741 has a selected CVSS score of 4.3 (medium).
Description
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 31, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
GrafanaBrowse Grafana / GrafanaDefault status: unaffected | CVE List | 11.4.0 to < 11.4.1 | affected |
| 11.3.0 to < 11.3.3 | affected | ||
| 11.2.0 to < 11.2.6 | affected | ||
| 11.1.0 to < 11.1.11 | affected | ||
| 10.4.0 to < 10.4.15 | affected | ||
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 11.4.0 | affected |
| 11.4.0 to < 11.4.1 · Fixed in 11.4.1 | affected | ||
| 11.3.0 to < 11.3.3 · Fixed in 11.3.3 | affected | ||
| 11.2.0 to < 11.2.6 · Fixed in 11.2.6 | affected | ||
| 11.1.0 to < 11.1.11 · Fixed in 11.1.11 | affected | ||
| 11.0.0 to < 11.0.11 · Fixed in 11.0.11 | affected | ||
| 1.9.2 to < 10.4.15 · Fixed in 10.4.15 | affected | ||
| Before 0.0.0-20250129224826-70073427041e · Fixed in 0.0.0-20250129224826-70073427041e | affected | ||
| 0.0.0 to < 1.9.2-0.20250129224826-70073427041e · Fixed in 1.9.2-0.20250129224826-70073427041e | affected |
References
6github.com
https://github.com/grafana/grafana/commit/70073427041e15c353e0d467b714527584765aea grafana.com
https://grafana.com/security/security-advisories/cve-2024-11741 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-11741 pkg.go.dev
https://pkg.go.dev/vuln/GO-2025-3438 security.netapp.com
https://security.netapp.com/advisory/ntap-20250509-0006