Stored XSS in ResourcePicker component
Advisory ID: | CVE-2022-23552 |
Published: | 2023-01-26 |
Product: | Grafana |
CVSS Score: | 7.3 |
CVSS Vector: | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Fixed Versions: | >=8.5.16 >=9.2.10 >=9.3.4 |
Summary
data:
scheme to load an inline SVG-file containing JavaScript. This means that vertical privilege escalation is possible, where a user with Editor role can change to a known password for a user having Admin role if the user with Admin role executes malicious JavaScript viewing a dashboard. Users may upgrade to version 8.5.16, 9.2.10, or 9.3.4 to receive a fix.