PT-2023-8919 · Grafana+5 · Grafana+5

Vtorosyan

·

Published

2023-01-26

·

Updated

2025-10-31

·

CVE-2022-23552

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions 8.1 through 8.5.15 Grafana versions 9.2.0 through 9.2.9 Grafana versions 9.3.0 through 9.3.3
Description Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance. An attacker needs to have the Editor role in order to change a panel to include either an external URL to a SVG-file containing JavaScript, or use the data: scheme to load an inline SVG-file containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.
Recommendations For versions 8.1 through 8.5.15, upgrade to version 8.5.16 to receive a fix. For versions 9.2.0 through 9.2.9, upgrade to version 9.2.10 to receive a fix. For versions 9.3.0 through 9.3.3, upgrade to version 9.3.4 to receive a fix.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6420
ALSA-2023_6420
ALSA-2025_16880
ALT-PU-2023-1132
ALT-PU-2023-1161
ALT-PU-2023-4567
BDU:2024-02615
BIT-GRAFANA-2022-23552
CVE-2022-23552
GHSA-8XMM-X63G-F6XV
OESA-2025-2547
OESA-2025-2548
OESA-2025-2549
OESA-2025-2550
OPENSUSE-SU-2024:12659-1
RHSA-2023:6420
RHSA-2023_6420
SUSE-SU-2023:0811-1
SUSE-SU-2023:0812-1
SUSE-SU-2023:0821-1
SUSE-SU-2023_0812-1
SUSE-SU-2024:0191-1
SUSE-SU-2024:0196-1

Affected Products

Alt Linux
Almalinux
Grafana
Red Hat
Red Os
Suse