PT-2024-7005 · Duckdb+3 · Duckdb+3
Published
2024-04-23
·
Updated
2026-03-11
·
CVE-2024-9264
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grafana versions prior to v11.0.6+security-01
Grafana versions prior to v11.1.7+security-01
Grafana versions prior to v11.2.2+security-01
Description
The SQL Expressions experimental feature of Grafana allows for the evaluation of
duckdb queries containing user input. These queries are insufficiently sanitized before being passed to duckdb, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The duckdb binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions. Over 538k results are found on ZoomEye, indicating a large number of potentially affected devices worldwide. The vulnerability is actively exploited in the wild.Recommendations
For versions prior to v11.0.6+security-01, update to v11.0.6+security-01 or later.
For versions prior to v11.1.7+security-01, update to v11.1.7+security-01 or later.
For versions prior to v11.2.2+security-01, update to v11.2.2+security-01 or later.
As a temporary workaround, consider disabling the SQL Expressions feature until a patch is available.
Restrict access to the
duckdb binary to minimize the risk of exploitation.
Avoid using the SQL Expressions feature with untrusted user input until the issue is resolved.Exploit
Fix
RCE
Command Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grafana
Red Os
Suse
Duckdb