CVE-2023-1410
Grafana vulnerability analysis and mitigation

Overview

A stored XSS vulnerability (CVE-2023-1410) was discovered in Grafana versions 8.0.0 prior to 8.5.22, 9.2.0 prior to 9.2.15, and 9.3.0 prior to 9.3.11. The vulnerability exists in the Graphite FunctionDescription tooltip feature where function descriptions were not properly sanitized (Grafana Advisory, GitHub Advisory).

Technical details

The vulnerability occurs when a Graphite data source is added to a dashboard. When using Functions feature, a tooltip appears when hovering over the function name, allowing users to delete the function or show its description. The vulnerability exists because no sanitization is performed when adding this description to the DOM. The issue is located in the file 'public/app/plugins/datasource/graphite/components/FunctionEditorControls.tsx' where rst2html parsing leaves HTML untouched, allowing XSS payloads to survive when applied using dangerouslySetInnerHTML (GitHub Advisory).

Impact

Successful exploitation could lead to disclosure of sensitive information or addition/modification of data. An attacker could execute arbitrary JavaScript in the victim's browser, potentially adding themselves as an admin if the victim has administrative privileges (NetApp Advisory, GitHub Advisory).

Mitigation and workarounds

Users should upgrade to Grafana versions 8.5.22, 9.2.15, 9.3.11, or 9.4.7 to receive the fix (Grafana Advisory).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23950HIGH8.8
  • GrafanaGrafana
  • nodejs:20::nodejs-packaging
NoNoJan 20, 2026
CVE-2026-22610HIGH8.5
  • JavaScriptJavaScript
  • polkit-docs
NoYesJan 10, 2026
CVE-2026-23745HIGH8.2
  • JavaScriptJavaScript
  • nodejs-full-i18n
NoYesJan 16, 2026
CVE-2026-22029HIGH8
  • JavaScriptJavaScript
  • ipa-selinux-luna
NoYesJan 10, 2026
CVE-2025-14505MEDIUM5.6
  • JavaScriptJavaScript
  • grafana-elasticsearch
NoNoJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management