CVE-2023-0594

Grafana is an open-source platform for monitoring and observability. 

Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the trace view visualization. 

The stored XSS vulnerability was possible due the value of a span's attributes/resources were not properly sanitized and this will be rendered when the span's attributes/resources are expanded.

An attacker needs to have the Editor role in order to change the value of a trace view visualization to contain JavaScript. 

This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. 

Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix. 

Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
GRAFANACNA
7.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
grafanagrafana
7.0.0 ≤
𝑥
< 8.5.21
grafanagrafana
9.2.0 ≤
𝑥
< 9.2.13
grafanagrafana
9.3.0 ≤
𝑥
< 9.3.8
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grafana
oracular
dne
noble
dne
mantic
dne
jammy
dne
focal
dne
xenial
needs-triage