QID 150659
Date Published: 2023-03-15
QID 150659: Grafana Multiple Stored Cross-Site Scripting Vulnerabilities (CVE-2023-0594,CVE-2023-0507)
Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
Grafana contains multiple vulnerabilities:
CVE-2023-0594: Grafana had a stored XSS vulnerability in its trace view visualization due to unsanitized span attributes/resources. An Editor can inject JavaScript and escalate privileges to access an Admin's known password via a malicious dashboard.
CVE-2023-0507: Grafana's GeoMap core plugin had a stored XSS vulnerability due to unsanitized map attributions allowing arbitrary JavaScript execution. An Editor could inject JavaScript to escalate privileges and access an Admin's known password via a malicious dashboard. It's recommended to update Grafana and restrict Editor role access.
Affected Versions:
Grafana versions from 7.0.0 to 8.5.21
Grafana versions from 9.2.0 to 9.2.13
Grafana versions from 9.3.0 to 9.3.8
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a Grafana running on the target application.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
- CVE-2023-0507 -
grafana.com/security/security-advisories/cve-2023-0507/ - CVE-2023-0594 -
grafana.com/security/security-advisories/cve-2023-0594/
CVEs related to QID 150659
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-0507 |
|
||
| CVE-2023-0594 |
|