Company
Date Published
Author
Grafana Labs Team
Word count
415
Language
English
Hacker News points
None

Summary

Grafana Labs has determined that it is not affected by the Spring4Shell vulnerability, which involves a potential remote code execution risk in certain versions of the Spring Cloud Function when using routing functionality. Despite the initial report of the vulnerability on March 29, 2022, and its ability to bypass patches for CVE-2010-1622 due to changes in Java Development Kit versions 9 and later, Grafana Labs has thoroughly reviewed its code base and related components, finding no evidence of impact. The company advises users to stay informed through security announcements and updates on their community site and offers a communication channel for reporting any security vulnerabilities. Additionally, updates and recommendations from CISA and VMware on addressing related vulnerabilities in the Spring Framework and Spring Cloud Function are emphasized.