First published: Mon May 29 2023(Updated: )
Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's also possible to cause this by calling the query API directly. This might enable malicious users to crash Grafana instances through that endpoint. Users may upgrade to version 9.4.12 and 9.5.3 to receive a fix.
Credit: security@grafana.com
Affected Software | Affected Version | How to fix |
---|---|---|
Grafana Grafana | >=9.4.0<9.4.12 | |
Grafana Grafana | >=9.5.0<9.5.3 | |
redhat/grafana | <9.4.12 | 9.4.12 |
redhat/grafana | <9.5.3 | 9.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2801 is a vulnerability in Grafana that can cause a crash when using mixed queries in public dashboards.
CVE-2023-2801 affects Grafana versions 9.4.0 to 9.4.12 and 9.5.0 to 9.5.3.
The severity of CVE-2023-2801 is high with a severity value of 5.3.
To fix CVE-2023-2801, upgrade Grafana to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-2801 on the Grafana and NetApp security advisories.