Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published: 2023-03-23T07:48:56.246Z

Updated: 2024-08-02T05:49:11.621Z

Reserved: 2023-03-15T11:11:52.860Z

Link: CVE-2023-1410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-03-23T08:15:12.470

Modified: 2024-11-21T07:39:08.240

Link: CVE-2023-1410

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-03-22T00:00:00Z

Links: CVE-2023-1410 - Bugzilla