Grafana is an open-source platform for monitoring and observability.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.
The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.
This vulnerability was fixed in version 1.2.2.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.
The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.
This vulnerability was fixed in version 1.2.2.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2626 | Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source. This vulnerability was fixed in version 1.2.2. |
Github GHSA |
GHSA-37x5-qpm8-53rq | Google Sheets data source plugin for Grafana information disclosure vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2024-09-16T16:38:55.837Z
Reserved: 2023-08-21T12:55:38.286Z
Link: CVE-2023-4457
Updated: 2024-08-02T07:31:05.355Z
Status : Modified
Published: 2023-10-16T10:15:12.057
Modified: 2024-11-21T08:35:12.207
Link: CVE-2023-4457
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA