CVE-2023-4457

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-4457
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4457.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4457
Aliases
Published
2023-10-16T10:15:12Z
Modified
2025-01-14T12:00:29.430098Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Grafana is an open-source platform for monitoring and observability.

The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.

The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.

This vulnerability was fixed in version 1.2.2.

References

Affected packages

Git / github.com/grafana/google-sheets-datasource

Affected ranges

Type
GIT
Repo
https://github.com/grafana/google-sheets-datasource
Events

Affected versions

v0.*

v0.9.0
v0.9.0-dev

v1.*

v1.1.0
v1.2.2