CVE-2023-0507

説明

A flaw was found in the GeoMap Grafana plugin, where a user can store unsanitized HTML in the GeoMap plugin under the Attribution text field, and the client will process it. The vulnerability makes it possible to use XHR to make arbitrary API calls on behalf of the attacked user. This means that a malicious user with editor permissions could alter a GeoMap panel to include JavaScript that changes the password for the user viewing the panel (this could be an admin) to a known password, thus gaining access to the admin account and resulting as the editor becoming an admin.

詳細

For Grafana package shipped in Red Hat Enterprise Linux, it is not possible to take advantage of this vulnerability without specialized 'editor' access, which reduces the impact of this issue in RHEL. Thus, it is set to Moderate.

軽減策

Applying the Content-Security-Policy shipped with Grafana would block inline scripts from executing and would mitigate this.

CVSS (Common Vulnerability Scoring System) のスコアの詳細

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 スコアの内訳

Red HatNVDcve.org
ベーススコア7.35.47.3
攻撃ベクトルNetworkNetworkNetwork
攻撃の複雑さLowLowLow
必要な権限LowLowLow
ユーザー関与レベルRequiredRequiredRequired
範囲UnchangedChangedUnchanged
機密性HighLowHigh
完全性への影響HighLowHigh
可用性への影響NoneNoneNone

ベクトル

Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

NVD: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

脆弱性の原因 (CWE) の理解

Confidentiality,Integrity,Availability

Technical Impact: Read Application Data; Execute Unauthorized Code or Commands

An attacker could insert special characters that are processed client-side in the context of the user's session.

謝辞

Upstream acknowledges Grafana Security Team as the original reporter.

よくある質問

エラータ通知の受信を希望しますか? こちらで登録してください。