CVE-2023-0594High· 7.3▾ TwilightA flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 1.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
9.2%
Last analysed / modified upstream
5.4 → 7.3
medium → high
A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known password, thus gaining access to the admin account.
grafana: cross site scripting — rated Important by Red Hat. Released 2023-03-01, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/2789521
and
https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5/html-single/upgrade_guide/index
For supported configurations, refer to:
https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:0746
Workarounds / mitigations:
Affected packages:
github.com/grafana/grafana >= 7.0.0, < 8.5.21github.com/grafana/grafana >= 9.0.0, < 9.2.13github.com/grafana/grafana >= 9.3.0, < 9.3.8Patched in:
github.com/grafana/grafana 8.5.21github.com/grafana/grafana 9.2.13github.com/grafana/grafana 9.3.8Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93433Medium· 5.5A flaw was found in libstoragemgmt
CVE-2026-92382Medium· 4.1An out-of-bounds write flaw was found in usbredir
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror
CVE-2026-94184High· 8.1A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support