{"id":"CVE-2024-8986","summary":"Information Leakage in grafana-plugin-sdk-go","details":"The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`.\n \nIf credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the final binary will contain the full URI, including said credentials.","aliases":["GHSA-xxxw-3j6h-q7h6","GO-2024-3140"],"modified":"2026-07-15T01:48:56.012860903Z","published":"2024-09-19T10:57:01.035Z","related":["CGA-9gx3-xp87-gxqc","openSUSE-SU-2024:14515-1"],"database_specific":{"cna_assigner":"GRAFANA","cwe_ids":["CWE-522"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8986.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8986.json"},{"type":"ADVISORY","url":"https://grafana.com/security/security-advisories/cve-2024-8986/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8986"},{"type":"PACKAGE","url":"https://github.com/grafana/grafana-plugin-sdk-go"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/grafana/grafana-plugin-sdk-go","events":[{"introduced":"f94df4a6f21dbe69dec4745793b71ecb71e07333"},{"last_affected":"41102661e6497e3dc9c8bcec9a734b674f163ceb"}],"database_specific":{"extracted_events":[{"introduced":"0.106.0"},{"last_affected":"0.249.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v0.249.0","v0.248.0","v0.247.0","v0.246.0","v0.245.0","v0.244.0","v0.243.0","v0.242.0","v0.241.0","v0.240.0","v0.239.0","v0.238.0","v0.237.0","v0.236.0","v0.235.0","v0.234.0","v0.233.0","v0.232.0","v0.231.0","v0.230.0","v0.229.0","v0.228.0","v0.227.0","v0.226.0","v0.225.0","v0.224.0","v0.223.0","v0.222.0","v0.221.0","v0.220.0","v0.219.0","v0.218.0","v0.217.0","v0.216.0","v0.215.0","v0.214.0","v0.213.0","v0.212.0","v0.211.0","v0.210.0","v0.209.0","v0.208.0","v0.207.0","v0.206.0","v0.205.0","v0.204.0","v0.203.0","v0.202.0","v0.201.0","v0.200.0","v0.199.0","v0.198.0","v0.197.0","v0.196.0","v0.195.0","v0.194.0","v0.193.0","v0.192.0","v0.191.0","v0.190.0","v0.189.0","v0.188.4","v0.188.3","v0.188.2","v0.188.1","v0.188.0","v0.187.0","v0.186.0","v0.185.0","v0.184.0","v0.183.0","v0.182.0","v0.181.0","v0.180.0","v0.179.0","v0.178.0","v0.177.0","v0.176.0","v0.175.0","v0.174.0","v0.173.0","v0.172.0","v0.171.0","v0.170.0","v0.169.0","v0.168.0","v0.167.0","v0.166.0","v0.165.0","v0.164.0","v0.163.0","v0.162.0","v0.161.0","v0.160.0","v0.159.0","v0.158.0","v0.157.0","v0.156.0","v0.155.0","v0.154.0","v0.153.0","v0.152.0","v0.151.0","v0.150.0","v0.149.1","v0.149.0","v0.148.0","v0.147.0","v0.146.0","v0.145.0","v0.144.0","v0.143.0","v0.142.0","v0.141.0","v0.140.0","v0.139.0","v0.138.0","v0.137.0","v0.136.0","v0.135.0","v0.134.0","v0.133.0","v0.132.0","v0.131.0","v0.130.0","v0.129.0","v0.128.0","v0.127.0","v0.126.0","v0.125.1","v0.125.0","v0.124.0","v0.114.0","v0.123.0","v0.122.0","v0.121.0","v0.120.0","v0.119.0","v0.118.0","v0.117.0","v0.116.0","v0.115.0","v0.113.0","v0.112.0","v0.111.0","v0.110.0","v0.109.0","v0.108.0","v0.107.0","v0.106.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8986.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/AU:Y/R:U/RE:L"}]}