PT-2023-8898 · Grafana+3 · Grafana+3

Renniepak

·

Publicado

2023-03-23

·

Atualizado

2024-06-15

·

CVE-2023-1410

CVSS v3.1

6.2

Média

VetorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 8.5.22 Grafana versions prior to 9.2.15 Grafana versions prior to 9.3.11
Description Grafana is an open-source platform for monitoring and observability. A stored XSS vulnerability was found in the Graphite FunctionDescription tooltip. The vulnerability is possible due to the value of the Function Description not being properly sanitized. An attacker needs to have control over the Graphite data source to manipulate a function description, and a Grafana admin needs to configure the data source. Later, a Grafana user needs to select a tampered function and hover over the description. This can allow an attacker to execute arbitrary JavaScript in the browser of the victim, potentially leading to adding the attacker as an admin.
Recommendations To resolve the issue, upgrade to version 8.5.22, 9.2.15, or 9.3.11 to receive a fix. As a temporary workaround, consider disabling the FunctionDescription feature until a patch is available. Restrict access to the Graphite data source to minimize the risk of exploitation. Avoid using the FunctionDescription tooltip in the affected API endpoint until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-4133
ALT-PU-2023-4148
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2024-02575
BIT-GRAFANA-2023-1410
CVE-2023-1410
GHSA-3CGW-HFW7-WC7J
GHSA-QRRG-GW7W-VP76
OPENSUSE-SU-2024:12855-1
SUSE-SU-2023:1902-1
SUSE-SU-2023:1903-1
SUSE-SU-2023:1904-1
SUSE-SU-2023:2575-1
SUSE-SU-2023:2578-1
SUSE-SU-2023:2579-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Produtos afetados

Alt Linux
Grafana
Red Os
Suse