VDB
BDU%3A2023-01776
BDU%3A2023-01776
PUBLISHED
CVSS 8.5 HIGH
Уязвимость панели Trace View веб-инструмента представления данных Grafana, позволяющая нарушителю повысить свои привилегии и осуществить межсайтовые сценарные атаки
Risk Scores
CVSS 2.0
8.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», Red Hat Inc., Grafana Labs | РЕД ОС (запись в едином реестре российских программ №3751), Red Hat Advanced Cluster Management for Kubernetes, Red Hat Ceph Storage, Grafana |
Timeline
- Apr 2, 2023 CVE Published
- Apr 5, 2024 CVE Updated
References
- https://grafana.com/docs/grafana/latest/explore/trace-integration/ url
- https://grafana.com/security/security-advisories/cve-2023-0594/ url
- https://access.redhat.com/security/cve/cve-2023-0594 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2168037 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory