PT-2023-2055 · Grafana+2 · Grafana+2

Published

2023-02-08

·

Updated

2024-04-05

·

CVE-2023-0594

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions 7.0 through 8.5.20 Grafana versions 9.2.0 through 9.2.12 Grafana versions 9.3.0 through 9.3.7
Description Grafana has a stored XSS vulnerability in the trace view visualization. The vulnerability is possible due to the value of a span's attributes/resources not being properly sanitized, which will be rendered when the span's attributes/resources are expanded. An attacker needs to have the Editor role to change the value of a trace view visualization to contain JavaScript, allowing for vertical privilege escalation where a user with Editor role can change a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.
Recommendations To resolve the issue, upgrade to version 8.5.21, 9.2.13, or 9.3.8 to receive a fix. As a temporary workaround, consider restricting the Editor role to minimize the risk of exploitation. Restrict access to the trace view visualization to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4133
ALT-PU-2023-4148
ALT-PU-2023-4346
ALT-PU-2023-4567
BDU:2023-01731
BDU:2023-01776
BIT-GRAFANA-2023-0594
BIT-GRAFANA-2023-22462
CVE-2023-0594
GHSA-7RQG-HJWC-6MJF
GHSA-XW5P-HW8J-XG4Q
SUSE-SU-2023:1902-1
SUSE-SU-2023:1903-1
SUSE-SU-2023:1904-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Grafana
Red Os