{"id":"GO-2024-3168","summary":"Grafana Alloy on Windows has Unquoted Search Path or Element vulnerability in github.com/grafana/alloy","details":"Grafana Alloy on Windows has Unquoted Search Path or Element vulnerability in github.com/grafana/alloy","aliases":["BIT-grafana-alloy-2024-8975","CVE-2024-8975","GHSA-chqx-36rm-rf8h"],"modified":"2026-03-03T04:55:49.788931Z","published":"2024-10-09T20:29:23Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-3168"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-chqx-36rm-rf8h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8975"},{"type":"FIX","url":"https://github.com/grafana/alloy/commit/88e779887690954c009503598a3f4bf563cb6596"},{"type":"FIX","url":"https://github.com/grafana/alloy/commit/f14249012fd970d3fd73604e6fff9b6c7990a9bb"},{"type":"WEB","url":"https://github.com/grafana/alloy/releases/tag/v1.3.4"},{"type":"WEB","url":"https://github.com/grafana/alloy/releases/tag/v1.4.0"},{"type":"WEB","url":"https://github.com/grafana/alloy/releases/tag/v1.4.1"},{"type":"WEB","url":"https://grafana.com/blog/2024/09/25/grafana-alloy-and-grafana-agent-flow-security-release-high-severity-fix-for-cve-2024-8975-and-cve-2024-8996"},{"type":"WEB","url":"https://grafana.com/security/security-advisories/cve-2024-8975"}],"affected":[{"package":{"name":"github.com/grafana/alloy","ecosystem":"Go","purl":"pkg:golang/github.com/grafana/alloy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.4"},{"introduced":"1.4.0-rc.0"},{"fixed":"1.4.1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-3168.json"}}],"schema_version":"1.7.3"}