Overview
About vulnerability
When using public dashboards and direct data-sources, all direct data-sources’ passwords are exposed despite not being used in dashboards.
No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments’ security.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Alpine Linux 3.22 , Alpine Linux 3.23 , Debian 12 , Debian 13 , Grafana , TuxCare 9.6 ESU
- Affected packages:
- github.com/grafana/grafana @ 11.3.0 (+20 more)
When using public dashboards and direct data-sources, all direct data-sources’ passwords are exposed despite not being used in dashboards.
No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments’ security.