CVE-2023-1410
Estado: ModificadaMedia (4.8)—
Grafana is an open-source platform for monitoring and observability.
Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip.
The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized.
An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.
Detalles técnicos trazas, registros y código del informe original
Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.96%
- Percentil entre todas las CVEs puntuadas: 60
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
- https://github.com/grafana/bugbounty/security/advisories/GHSA-qrrg-gw7w-vp76
- https://grafana.com/security/security-advisories/cve-2023-1410/
- https://security.netapp.com/advisory/ntap-20230420-0003/
- https://github.com/grafana/bugbounty/security/advisories/GHSA-qrrg-gw7w-vp76
- https://grafana.com/security/security-advisories/cve-2023-1410/
- https://security.netapp.com/advisory/ntap-20230420-0003/
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-1410",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-1410",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-03-04T21:21:42.873495Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@grafana.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.2,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 4.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 1.7
}
]
},
"affected": [
{
"source": "security@grafana.com",
"affectedData": [
{
"vendor": "Grafana",
"product": "Grafana",
"versions": [
{
"status": "affected",
"version": "8.0.0",
"lessThan": "8.5.22",
"versionType": "semver"
},
{
"status": "affected",
"version": "9.0.0",
"lessThan": "9.2.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "9.3.0",
"lessThan": "9.3.11",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Grafana",
"product": "Grafana Enterprise",
"versions": [
{
"status": "affected",
"version": "8.0.0",
"lessThan": "8.5.22",
"versionType": "semver"
},
{
"status": "affected",
"version": "9.0.0",
"lessThan": "9.2.15",
"versionType": "semver"
},
{
"status": "affected",
"version": "9.3.0",
"lessThan": "9.3.11",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-03-23T08:15:12.470",
"references": [
{
"url": "https://github.com/grafana/bugbounty/security/advisories/GHSA-qrrg-gw7w-vp76",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security@grafana.com"
},
{
"url": "https://grafana.com/security/security-advisories/cve-2023-1410/",
"tags": [
"Vendor Advisory"
],
"source": "security@grafana.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20230420-0003/",
"source": "security@grafana.com"
},
{
"url": "https://github.com/grafana/bugbounty/security/advisories/GHSA-qrrg-gw7w-vp76",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://grafana.com/security/security-advisories/cve-2023-1410/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20230420-0003/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@grafana.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Grafana is an open-source platform for monitoring and observability. \n\nGrafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. \n\nThe stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized.\n\nAn attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description. \n\n Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix."
}
],
"lastModified": "2026-06-17T05:27:54.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7482331-D381-4704-BF90-060DB1E279C1",
"versionEndExcluding": "8.5.22",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79D0AE4D-AD37-45A8-A84B-FE675F2D2943",
"versionEndExcluding": "9.2.15",
"versionStartIncluding": "9.2.0"
},
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D6B0083-7414-4C30-9C14-B4C4784F79DB",
"versionEndExcluding": "9.3.11",
"versionStartExcluding": "9.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@grafana.com"
}