CVE-2023-1410Cross-site Scripting in Grafana

Severity
4.8MEDIUMNVD
CNA6.2
EPSS
2.0%
top 16.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23

Description

Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages4 packages

CVEListV5grafana/grafana8.0.08.5.22+2
NVDgrafana/grafana8.0.08.5.22+2
CVEListV5grafana/grafana_enterprise8.0.08.5.22+2
Gogithub.com/grafana_grafana8.0.08.5.22+3

🔴Vulnerability Details

4
OSV
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip2023-03-23
GHSA
Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip2023-03-23
OSV
CVE-2023-1410: Grafana is an open-source platform for monitoring and observability2023-03-23
CVEList
Stored XSS in Graphite FunctionDescription tooltip2023-03-23

📋Vendor Advisories

1
Red Hat
grafana: Stored XSS in Graphite FunctionDescription tooltip2023-03-22
CVE-2023-1410 — Cross-site Scripting in Grafana | cvebase