Stored XSS Vulnerability in Grafana Monitoring Platform
CVE-2023-0594
What is CVE-2023-0594?
Grafana, an open-source platform for monitoring and observability, has a vulnerability that allows attackers with Editor privileges to inject malicious JavaScript into trace view visualizations. Due to improper sanitization of span attributes, this XSS vulnerability enables an attacker to execute harmful scripts within the context of another user's session, potentially allowing vertical privilege escalation. Affected users are advised to upgrade to the fixed versions of Grafana to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Grafana 7.0.0 < 8.5.21
Grafana 9.0.0 < 9.2.13
Grafana 9.3.0 < 9.3.8
References
EPSS Score
52% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved