Back

CRITICAL

Grafana SQL Expressions allow for remote code execution

Published Oct 18, 2024

Description

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distributions.

Affected products

Remediation

Red Hat statement

This vulnerability is classified as critical instead of important because it allows for command injection and local file inclusion, potentially leading to arbitrary code execution or unauthorized access to sensitive files. The exploit can be carried out by any user with VIEWER or higher permissions, significantly increasing the attack surface. Moreover, due to an incorrect implementation of feature flags, the SQL Expressions feature is enabled by default for the API, making it more likely to be exposed in affected deployments. Although the vulnerability requires the presence of the DuckDB binary in the Grafana process's PATH, systems that meet this condition are at significant risk. It’s important to note that this issue was introduced in a Grafana version not included in any Red Hat offerings, ensuring that Red Hat customers are not impacted.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (9)

Change history (3)
  1. CISA ADP
    • SSVC exploitation changed from poc to none
  2. CISA ADP
    • SSVC exploitation changed from none to poc
  3. CISA ADP
    • SSVC exploitation changed from poc to none
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GRAFANA
Published Oct 18, 2024
Updated Mar 14, 2025
Reserved Sep 26, 2024
CISA Vulnrichment
Updated Oct 18, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Oct 24, 2024
GHSA-Q99M-QCV4-FPM7