HIGH 7.3 Go
Grafana Agent (Flow mode) on Windows has Unquoted Search Path or Element vulnerability
GHSA-m5gv-m5f9-wgv4 · CVE-2024-8996 · GO-2024-3170
Published · Modified
Description
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM.
This issue affects Agent Flow before 0.43.3.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-8996
- WEB https://github.com/grafana/agent/commit/91bab2c05906938d3f8e1e3c61a863f037985299
- PACKAGE https://github.com/grafana/agent
- WEB https://github.com/grafana/agent/releases/tag/v0.43.2
- WEB https://github.com/grafana/agent/releases/tag/v0.43.3
- WEB https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996
- WEB https://grafana.com/security/security-advisories/cve-2024-8996
- WEB https://pkg.go.dev/vuln/GO-2024-3170
Ready to move
Start Securing
Free, no credit card | First findings in minutes