Package
grafana-fips-12.1
Component
github.com/grafana/grafana
Latest update
5.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2020-12459 affected Grafana version 6.x (fixed in 6.3.6) and related to permissions set by RPM and DEB packages.
This detection is a false-positive, triggered by the record in Go's vulnDB (GO-2024-2519) only including a Fixed version in the "Custom Versions" field (which is not currently consumed by Grype - https://github.com/anchore/grype/issues/3510)
Status
Impact
This package is no longer supported upstream and has reached its end of life. A version upgrade is required to fix this vulnerability.
Status