SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Grafana SQL Expressions Local File Inclusion

Category: WEB-ATTACKS      

A vulnerability discovered in Grafana 11, which is in an experimental feature named SQL Expressions that allows for data source query output to be post-processed by executing one or more SQL queries. It does this by passing the query and data to the DuckDB CLI, which executes the SQL against the DataFrame data. These SQL queries were not sanitized completely, leading to a command injection and local file inclusion vulnerability.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1911


Relevant Information