• CVE-2023-1410

发布时间: 2023年4月18日

修改时间: 2023年4月18日

概要

Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description. Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS v3 指标

NVD openEuler
CVSS评分 4.8 4.8
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required High High
User Interaction Required Required
Scope Changed Changed
Confidentiality Low Low
Integrity Low Low
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1282 Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description. Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix. 2023年4月18日

影响产品

产品 状态
KY3.4-4A grafana Unaffected
KY3.4-5A grafana Unaffected
KY3.5.1 grafana Unaffected
KY3.5.2 grafana Unaffected