PT-2023-8916 · Grafana+1 · Grafana Google Sheets Data Source Plugin+1

CVE-2023-4457

·

Publicado

2023-10-16

·

Atualizado

2024-04-05

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana Google Sheets data source plugin versions 0.9.0 through 1.2.1
Description The Google Sheets data source plugin for Grafana is vulnerable to an information disclosure issue due to improper sanitization of error messages. This could potentially expose the Google Sheet API-key configured for the data source.
Recommendations For versions 0.9.0 through 1.2.1, update to version 1.2.2 to resolve the issue. As a temporary workaround, consider restricting access to the Google Sheets data source plugin until the update is applied.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02600
CVE-2023-4457
GHSA-37X5-QPM8-53RQ
GO-2023-2158

Produtos afetados

Grafana Google Sheets Data Source Plugin
Red Os