Moderate severityNVD Advisory· Published Sep 25, 2024· Updated Sep 26, 2024
Grafana Agent Flow on Windows Unquoted service path
CVE-2024-8996
Description
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/grafana/agentGo | < 0.43.3 | 0.43.3 |
Affected products
8- ghsa-coords7 versionspkg:golang/github.com/grafana/agentpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/govulncheck-vulndb&distro=SUSE%20Package%20Hub%2012
< 0.43.3+ 6 more
- (no CPE)range: < 0.43.3
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241030T212825-1.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241030T212825-150000.1.9.1
- (no CPE)range: < 0.0.20241104T154416-5.1
- Grafana/Agent Flowv5Range: 0
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-m5gv-m5f9-wgv4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-8996ghsaADVISORY
- github.com/grafana/agent/commit/91bab2c05906938d3f8e1e3c61a863f037985299ghsaWEB
- github.com/grafana/agent/releases/tag/v0.43.2ghsaWEB
- github.com/grafana/agent/releases/tag/v0.43.3ghsaWEB
- grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996ghsaWEB
- grafana.com/security/security-advisories/cve-2024-8996ghsaWEB
- pkg.go.dev/vuln/GO-2024-3170ghsaWEB
- grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996/mitre
- grafana.com/security/security-advisories/cve-2024-8996/mitre
News mentions
0No linked articles in our index yet.