HomeGrafanaCVE-2023-1410

CVE-2023-1410

MEDIUM
6.2CVSS
Published: 2023-03-23
Updated: 2025-02-13
AI Analysis

Description

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:N
Attack Vector
network
Complexity
high
Privileges
high
User Action
required
Scope
changed
Confidentiality
high
Integrity
low
Availability
none
Weaknesses
CWE-79CWE-79

Metadata

Primary Vendor
GRAFANA
Published
3/23/2023
Last Modified
2/13/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

grafana : grafanagrafana : grafanagrafana : grafana

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2023-1410 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com