PT-2023-2055 · Grafana+2 · Grafana+2

Publicado

2023-02-08

·

Atualizado

2024-04-05

·

CVE-2023-0594

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions 7.0 through 8.5.20 Grafana versions 9.2.0 through 9.2.12 Grafana versions 9.3.0 through 9.3.7
Description Grafana has a stored XSS vulnerability in the trace view visualization. The vulnerability is possible due to the value of a span's attributes/resources not being properly sanitized, which will be rendered when the span's attributes/resources are expanded. An attacker needs to have the Editor role to change the value of a trace view visualization to contain JavaScript, allowing for vertical privilege escalation where a user with Editor role can change a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.
Recommendations To resolve the issue, upgrade to version 8.5.21, 9.2.13, or 9.3.8 to receive a fix. As a temporary workaround, consider restricting the Editor role to minimize the risk of exploitation. Restrict access to the trace view visualization to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4133
ALT-PU-2023-4148
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2023-01731
BDU:2023-01776
BIT-GRAFANA-2023-0594
BIT-GRAFANA-2023-22462
CVE-2023-0594
GHSA-7RQG-HJWC-6MJF
GHSA-XW5P-HW8J-XG4Q
SUSE-SU-2023:1902-1
SUSE-SU-2023:1903-1
SUSE-SU-2023:1904-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Produtos afetados

Alt Linux
Grafana
Red Os