/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-7j69-4c5m-2mg2

Published

Last updated

https://images.chainguard.dev/security/CGA-7j69-4c5m-2mg2
Package

grafana-11.2

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2024-8986
  • GHSA-xxxw-3j6h-q7h6

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-8986

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

The vulnerability applies to build scripts in the grafana-go-sdk, not the library itself. Further, we don't pass sensitive information in our git clone urls so our builds of grafana would not be affected anyway.

Status

Pending upstream fix

Impact

Remediating this CVE requires upgrading to v0.250.0 or later of the 'grafana-plugin-sdk-go'. Upgrading this plugin in the current version of the code, results in build issues.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing