Grafana is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
43
Medium Risk
Affected versions of this package allow unauthorized access to DingDing contact points, potentially exposing configured DingDing alerting URLs to users with Viewer permissions and leaking sensitive data. An attacker with Viewer access can retrieve the DingDing integration URL, including API keys, enabling unauthorized interactions with the DingDing alerting service.
You are affected if you are using a version that falls within the vulnerable range.
Grafana is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 10.0.0 - 10.4.18, 11.0.0 - 11.2.9, 11.3.0 - 11.3.7, 11.4.0 - 11.4.5, 11.5.0 - 11.5.5, 11.6.0 - 11.6.2 and 12.0.0 - 12.0.0.
Upgrade the Grafana library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant