PT-2024-14076 · Grafana · Grafana Json Datasource Plugin

Isacaya

+1

·

Published

2024-02-14

·

Updated

2026-01-06

·

CVE-2023-5123

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana JSON datasource plugin (affected versions not specified)
Description The JSON datasource plugin for Grafana allows retrieving and processing JSON data from a remote endpoint. Due to inadequate sanitization of the dashboard-supplied path parameter, it is possible to include path traversal characters (../) and send requests to paths outside the configured sub-path. This means an editor can create a dashboard that issues queries with path traversal characters, causing the datasource to query arbitrary subpaths on the configured domain. In rare cases where the plugin is configured to point back at the Grafana instance itself, this issue can lead to privilege escalation as an administrator browsing a maliciously configured panel could be compelled to make requests to Grafana administrative API endpoints with their credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-5123

Affected Products

Grafana Json Datasource Plugin