QID 150668

Date Published: 2023-04-17

QID 150668: Grafana Stored Cross Site Scripting Vulnerability (CVE-2023-1410)

Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.

Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.

Affected Versions:
Grafana versions from 8.1.0 to 8.5.21
Grafana versions from 9.0.0 to 9.2.14
Grafana versions from 9.3.0 to 9.3.10

QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a Grafana running on the target application.

Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.

  • CVSS V3 rated as Medium - 4.8 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to upgrade to Grafana to latest version to remediate this vulnerability. For more information regarding this vulnerability please refer Grafana Advisory.

    CVEs related to QID 150668

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-1410 URL Logo grafana.com/security/security-advisories/cve-2023-1410/