CVE-2024-5526: SSRF
Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers.
Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vulnerability in the webhook functionallity.
This issue was fixed in version 1.5.2
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Grafana OnCallto a version that resolves this vulnerability.Fixed in 1.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5526?
CVE-2024-5526 is classified as a critical vulnerability due to its potential for Server Side Request Forgery (SSRF).
How do I fix CVE-2024-5526?
To fix CVE-2024-5526, upgrade your Grafana OnCall to version 1.5.2 or later.
Which versions of Grafana OnCall are affected by CVE-2024-5526?
CVE-2024-5526 affects Grafana OnCall versions 1.1.37 through 1.5.1.
What type of vulnerability is CVE-2024-5526?
CVE-2024-5526 is a Server Side Request Forgery (SSRF) vulnerability.
What are the potential impacts of CVE-2024-5526?
The impacts of CVE-2024-5526 may include unauthorized access to internal services and potentially sensitive data exposure.