Grafana tempo是Grafana公司开源的一个分布式追踪后端服务。 Grafana Tempo 2.8.8之前版本和Grafana Tempo 2.10.2之前版本存在安全漏洞,该漏洞源于TraceQL查询中大量exemplars hint值导致内存分配过多,可能允许已认证用户触发拒绝服务攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Enterprise Traces (GET) | 2.6.1< 2.8.8 |
affected |
| Grafana | Tempo | 2.6.0< 2.10.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Enterprise Traces (GET) | 2.6.1 ~ 2.8.8 | - |
|
| Grafana | Tempo | 2.6.0 ~ 2.10.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet