SCA: security update for github.com/grafana/grafana (GHSA-qrrg-gw7w-vp76)

medium Tenable Self-Hosted Container Security Plugin ID 418311

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS
vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due
the value of the Function Description was not properly sanitized. An attacker needs to have control over
the Graphite data source in order to manipulate a function description and a Grafana admin needs to
configure the data source, later a Grafana user needs to select a tampered function and hover over the
description. Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix. (CVE-2023-1410)

See Also

https://github.com/advisories/GHSA-qrrg-gw7w-vp76

Plugin Details

Severity: Medium

ID: 418311

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.14

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N

CVSS Score Source: CVE-2023-1410

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/23/2023

Vulnerability Publication Date: 3/23/2023

Reference Information

CVE: CVE-2023-1410

cwe: CWE-79