Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*
- >= 11, < 11.5.0
- >= 11, < 11.4.1
- >= 11, < 11.3.3
- >= 11, < 11.2.6
- >= 11, < 11.1.11
- >= 11, < 11.0.11
- >= 10, < 10.4.15
A vulnerability exists in the Grafana Alerting VictorOps integration, where improper protection could expose sensitive information to users with Viewer permission. This issue is present in Grafana versions prior to 11.5.0, as well as in versions 11.4.0, 11.3.0, 11.2.0, 11.1.0, 11.0.0, and 10.4.0.
Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information.
Users can upgrade to Grafana versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11, or 10.4.15 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.