QID 730754
Date Published: 2023-03-13
QID 730754: Grafana Stored Cross-Site Scripting (XSS) Vulnerability
Grafana is a multi-platform open source analytics and interactive visualization web application. It provides charts, graphs, and alerts for the web when connected to supported data sources.
CVE-2023-0594: Grafana had a stored XSS vulnerability in its trace view visualization due to unsanitized span attributes/resources. An Editor can inject JavaScript and escalate privileges to access an Admin's known password via a malicious dashboard.
Affected Versions:
Grafana versions from 7.0.0 prior to 8.5.21
Grafana versions from 9.2.0 prior to 9.2.13
Grafana versions from 9.3.0 prior to 9.3.8
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Grafana from the server response
Successful exploitation of this vulnerability may allow an attacker with an Editor role to change to a known password for a user with an Admin role and, with the Admin role permissions, can execute malicious JavaScript viewing a dashboard.
- Grafana Security Advisory -
grafana.com/security/security-advisories/cve-2023-0594/
CVEs related to QID 730754
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Grafana Security Advisory |
|