PT-2026-84757 · Postgresql Global Development Group+3 · Postgresql+3
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Grafana versions prior to 12.4.10-1.1
Description
An authenticated user with permissions to query a SQL data source can cause a denial of service by injecting the
timeGroup macro through a WHERE clause. Because the regex-based macro parsing does not reject this injection, evaluating the macro leads to uncontrolled memory consumption, which can terminate the server process. This issue affects Microsoft SQL Server, PostgreSQL, and MySQL data sources.Recommendations
Update to version 12.4.10-1.1.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana
Sql Server
Mysql Server
Postgresql