CVE-2024-8986
概要

The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`.

If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.

公表日 2024年9月19日20:15
登録日 2024年9月20日5:00
最終更新日 2024年9月20日21:30
関連情報、対策とツール
共通脆弱性一覧