Lucene search

K
freebsdFreeBSDE7841611-B808-11ED-B695-6C3BE5272ACD
HistoryJan 30, 2023 - 12:00 a.m.

Grafana -- Stored XSS in TraceView panel

2023-01-3000:00:00
vuxml.freebsd.org
12
grafana labs
stored xss
traceview panel
internal audit
january 30
cvss score 7.3 high
vulnerability
span attributes
resources
sanitized

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

64.5%

Grafana Labs reports:

During an internal audit of Grafana on January 30, a member
of the engineering team found a stored XSS vulnerability affecting
the TraceView panel.
The stored XSS vulnerability was possible because the value of a span’s
attributes/resources were not properly sanitized, and this will be rendered
when the span’s attributes/resources are expanded.
The CVSS score for this vulnerability is 7.3 High
(CVSS:7.3/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

64.5%