CVE-2023-4457: High severity google sheets vulnerability
Grafana is an open-source platform for monitoring and observability.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.
The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.
This vulnerability was fixed in version 1.2.2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4457?
CVE-2023-4457 is an information disclosure vulnerability in the Google Sheets data source plugin for Grafana.
What is Grafana?
Grafana is an open-source platform for monitoring and observability.
What is the severity of CVE-2023-4457?
The severity of CVE-2023-4457 is high with a CVSS score of 7.5.
How does CVE-2023-4457 affect Grafana?
CVE-2023-4457 affects Grafana through the Google Sheets data source plugin.
How can CVE-2023-4457 be fixed?
To fix CVE-2023-4457, users should upgrade their Google Sheets data source plugin for Grafana to version 1.2.3 or above.