Moderate severityNVD Advisory· Published Sep 25, 2024· Updated Sep 26, 2024
Grafana Alloy on Windows Unquoted service path
CVE-2024-8975
Description
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/alloyGo | < 1.3.4 | 1.3.4 |
github.com/grafana/alloyGo | >= 1.4.0-rc.0, < 1.4.1 | 1.4.1 |
Affected products
10- osv-coords9 versionspkg:bitnami/grafana-alloypkg:golang/github.com/grafana/alloypkg:rpm/opensuse/alloy&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Package%20Hub%2012
>= 1.4.0-rc0, <= 1.4.0-rc0+ 8 more
- (no CPE)range: >= 1.4.0-rc0, <= 1.4.0-rc0
- (no CPE)range: < 1.3.4
- (no CPE)range: < 1.4.3-1.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241030T212825-1.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241104T154416-5.1
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-chqx-36rm-rf8hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8975ghsaADVISORY
- github.com/grafana/alloy/commit/88e779887690954c009503598a3f4bf563cb6596ghsaWEB
- github.com/grafana/alloy/commit/f14249012fd970d3fd73604e6fff9b6c7990a9bbghsaWEB
- github.com/grafana/alloy/releases/tag/v1.3.4ghsaWEB
- github.com/grafana/alloy/releases/tag/v1.4.0ghsaWEB
- github.com/grafana/alloy/releases/tag/v1.4.1ghsaWEB
- grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996ghsaWEB
- grafana.com/security/security-advisories/cve-2024-8975ghsaWEB
- pkg.go.dev/vuln/GO-2024-3168ghsaWEB
- grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996/mitre
- grafana.com/security/security-advisories/cve-2024-8975/mitre
News mentions
0No linked articles in our index yet.