{"id":"CVE-2023-0594","title":"grafana: cross site scripting (CVE-2023-0594)","summary":"A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","cvssSource":"vendor","cwe":"CWE-80","vendor":"Red Hat","product":"Red Hat Ceph Storage 5.3 Tools","affected":["openshift_service_mesh 2.1","advanced_cluster_management_for_kubernetes 2","ceph_storage_5_3_tools"],"patched":["ceph_storage_5_3_tools"],"published":"2023-03-01","updated":"2026-09-17","sourceUpdated":"2026-09-17T13:55:39+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0594.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0594.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-0594"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2168037"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-0594"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0594"},{"url":"https://grafana.com/security/security-advisories/CVE-2023-0594"},{"url":"https://access.redhat.com/errata/RHSA-2024:0746"},{"url":"https://github.com/grafana/grafana"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.09216,"epssPercentile":0.95114,"aliases":["GHSA-xw5p-hw8j-xg4q","BIT-grafana-2023-0594"],"ecosystem":"go","scores":{"vendor":7.3,"osv":5.4},"ingestedAt":"2026-08-07T19:14:17.963Z","slug":"CVE-2023-0594","body":"## Overview\n\nA flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known password, thus gaining access to the admin account.\n\n## Vendor advisories\n\n- **RHSA-2024:0746** · Red Hat · fixed in: Red Hat Ceph Storage 5.3 Tools · released 2024-02-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:0746)\n- **Red Hat VEX** · Important · affected: OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Management for Kubernetes 2 · no fix planned: OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Management for Kubernetes 2 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0594.json)\n\n**grafana: cross site scripting** — rated Important by Red Hat. Released 2023-03-01, updated 2026-09-17.\n\nAffected:\n\n- OpenShift Service Mesh 2.1\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\nFixed:\n\n- Red Hat Ceph Storage 5.3 Tools\n\nNo fix planned:\n\n- OpenShift Service Mesh 2.1\n- Red Hat Advanced Cluster Management for Kubernetes 2\n\nNot affected:\n\n- Red Hat Ceph Storage 5.3 Tools\n- Red Hat Ceph Storage 3\n- Red Hat Ceph Storage 4\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat Storage 3\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/2789521\n\nand \n\nhttps://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5/html-single/upgrade_guide/index\n\nFor supported configurations, refer to:\n\nhttps://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:0746\n\nWorkarounds / mitigations:\n\n- Applying the Content-Security-Policy shipped with Grafana would block inline scripts from executing and would mitigate this.\n\n## Package advisory (CVE-2023-0594)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 7.0.0, < 8.5.21`\n- `github.com/grafana/grafana >= 9.0.0, < 9.2.13`\n- `github.com/grafana/grafana >= 9.3.0, < 9.3.8`\n\nPatched in:\n\n- `github.com/grafana/grafana 8.5.21`\n- `github.com/grafana/grafana 9.2.13`\n- `github.com/grafana/grafana 9.3.8`\n\nSource: https://osv.dev/vulnerability/GHSA-xw5p-hw8j-xg4q","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":40.2,"likelihood":1.8,"exploitation":0,"ransomware":0},"changes":[{"seq":206314,"id":"CVE-2023-0594","ts":1789663201747,"field":"cvss","old":"5.4","new":"7.3"},{"seq":206313,"id":"CVE-2023-0594","ts":1789663201747,"field":"severity","old":"medium","new":"high"}]}