CVE-2024-11741: Grafana

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3,  11.2.6, 11.1.11, 11.0.11 and 10.4.15

Affected products

  • Grafana Grafana: from 11.4.0, before 11.4.1 (fixed in 11.4.1); from 11.3.0, before 11.3.3 (fixed in 11.3.3); from 11.2.0, before 11.2.6 (fixed in 11.2.6); from 11.1.0, before 11.1.11 (fixed in 11.1.11); from 10.4.0, before 10.4.15 (fixed in 10.4.15)

Published 2025-01-31. Last modified 2026-06-17.