The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission.
Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0215 | Grafana Alerting VictorOps integration could be exposed to users with Viewer permission |
Github GHSA |
GHSA-wxcc-2f3q-4h58 | Grafana Alerting VictorOps integration could be exposed to users with Viewer permission |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 09 May 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 01 Feb 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | grafana: From CVEorg collector | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 31 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15 | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-05-09T20:03:33.716Z
Reserved: 2024-11-26T13:17:13.248Z
Link: CVE-2024-11741
Updated: 2025-05-09T20:03:33.716Z
Status : Awaiting Analysis
Published: 2025-01-31T16:15:30.853
Modified: 2025-05-09T20:15:38.060
Link: CVE-2024-11741
OpenCVE Enrichment
Updated: 2025-07-12T22:23:17Z
EUVD
Github GHSA