CVE-2023-4457
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2023
Last modified:
20/10/2023
Description
Grafana is an open-source platform for monitoring and observability.<br />
<br />
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.<br />
<br />
The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.<br />
<br />
This vulnerability was fixed in version 1.2.2.<br />
<br />
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:grafana:google_sheets:*:*:*:*:*:grafana:*:* | 0.9.0 (including) | 1.2.2 (including) |
To consult the complete list of CPE names with products and versions, see this page



