Back

HIGH

grafana: cross site scripting

Published Mar 1, 2023

Description

Grafana is an open-source platform for monitoring and observability.

Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap.

The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.

An attacker needs to have the Editor role in order to change a panel to include a map attribution containing JavaScript.

This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard.

Users may upgrade to version 8.5.21, 9.2.13 and 9.3.8 to receive a fix.

Affected products

Remediation

Red Hat statement

For Grafana package shipped in Red Hat Enterprise Linux, it is not possible to take advantage of this vulnerability without specialized 'editor' access, which reduces the impact of this issue in RHEL. Thus, it is set to Moderate.

Red Hat mitigation

Applying the Content-Security-Policy shipped with Grafana would block inline scripts from executing and would mitigate this.

References (9)

Change history (3)
  1. CISA ADP
    • SSVC technical impact

      changed from total to partial

  2. CISA ADP
    • SSVC technical impact

      changed from partial to total

  3. CISA ADP
    • SSVC technical impact

      changed from total to partial

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GRAFANA
Published Mar 1, 2023
Updated Jan 28, 2026
Reserved Jan 25, 2023
CISA Vulnrichment
Updated Mar 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 1, 2023
ENISA EUVD
Assigner GRAFANA
Published Mar 1, 2023
Updated Jan 28, 2026
Exploited since n/a
EUVD-2023-1035 GHSA-HJV9-HM2F-RPCJ