---
id: CVE-2023-0594
title: 'grafana: cross site scripting (CVE-2023-0594)'
summary: >-
  A flaw was found in the grafana package. This flaw allows a malicious user
  with the ability to introduce trace data to provide a JavaScript that changes
  the password for the user viewing the trace view (this could be an admin) to a
  known p…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-80
vendor: Red Hat
product: Red Hat Ceph Storage 5.3 Tools
affected:
  - openshift_service_mesh 2.1
  - advanced_cluster_management_for_kubernetes 2
  - ceph_storage_5_3_tools
patched:
  - ceph_storage_5_3_tools
published: '2023-03-01'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:55:39+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0594.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0594.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-0594'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2168037'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-0594'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-0594'
  - url: 'https://grafana.com/security/security-advisories/CVE-2023-0594'
  - url: 'https://access.redhat.com/errata/RHSA-2024:0746'
  - url: 'https://github.com/grafana/grafana'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.09216
epssPercentile: 0.95166
aliases:
  - GHSA-xw5p-hw8j-xg4q
  - BIT-grafana-2023-0594
ecosystem: go
scores:
  vendor: 7.3
  osv: 5.4
ingestedAt: '2026-08-07T19:14:17.963Z'
---

## Overview

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known password, thus gaining access to the admin account.

## Vendor advisories

- **RHSA-2024:0746** · Red Hat · fixed in: Red Hat Ceph Storage 5.3 Tools · released 2024-02-08 · [advisory](https://access.redhat.com/errata/RHSA-2024:0746)
- **Red Hat VEX** · Important · affected: OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Management for Kubernetes 2 · no fix planned: OpenShift Service Mesh 2.1, Red Hat Advanced Cluster Management for Kubernetes 2 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-0594.json)

**grafana: cross site scripting** — rated Important by Red Hat. Released 2023-03-01, updated 2026-09-17.

Affected:

- OpenShift Service Mesh 2.1
- Red Hat Advanced Cluster Management for Kubernetes 2

Fixed:

- Red Hat Ceph Storage 5.3 Tools

No fix planned:

- OpenShift Service Mesh 2.1
- Red Hat Advanced Cluster Management for Kubernetes 2

Not affected:

- Red Hat Ceph Storage 5.3 Tools
- Red Hat Ceph Storage 3
- Red Hat Ceph Storage 4
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4
- Red Hat Storage 3

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/2789521

and 

https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5/html-single/upgrade_guide/index

For supported configurations, refer to:

https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:0746

Workarounds / mitigations:

- Applying the Content-Security-Policy shipped with Grafana would block inline scripts from executing and would mitigate this.

## Package advisory (CVE-2023-0594)

Affected packages:

- `github.com/grafana/grafana >= 7.0.0, < 8.5.21`
- `github.com/grafana/grafana >= 9.0.0, < 9.2.13`
- `github.com/grafana/grafana >= 9.3.0, < 9.3.8`

Patched in:

- `github.com/grafana/grafana 8.5.21`
- `github.com/grafana/grafana 9.2.13`
- `github.com/grafana/grafana 9.3.8`

Source: https://osv.dev/vulnerability/GHSA-xw5p-hw8j-xg4q
