Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-4457

23
FAUCET Score

CVE-2023-4457 is an information disclosure vulnerability affecting the Google Sheets data source plugin for Grafana, specifically versions 0.9.0 to 1.2.2. The flaw stems from improper sanitization of error messages, which could inadvertently expose the configured Google Sheet API key. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, posing a significant risk of confidentiality compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.9.0, <= 1.2.2CPE matchmatch criteria
cpe:2.3:a:grafana:google_sheets:*:*:*:*:*:grafana:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 11th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

gopatch availablevia ghsa
Product: github.com/grafana/google-sheets-datasourceFixed in: 1.2.2
nodejspatch availablevia llm_extracted
View patch
apollographqlvendor investigatingvia llm_extracted
View patch
chainsafevendor investigatingvia llm_extracted
View patch
jenkinsvendor investigatingvia llm_extracted
View patch
kenticovendor investigatingvia llm_extracted
View patch
zimbravendor investigatingvia llm_extracted
View patch

Vendor Advisories (7)

goGHSA-37x5-qpm8-53rqmedium

Google Sheets data source plugin for Grafana information disclosure vulnerability

Oct 16, 2023
zimbrallm-zimbra-781c97bd0884412bMEDIUM

Information Disclosure in Google Sheets Plugin in Grafana

Sep 19, 2023
kenticollm-kentico-6b55e407a3065b66MEDIUM

Information Disclosure in Google Sheets Plugin in Grafana

Sep 19, 2023
chainsafellm-chainsafe-fc85ef8fcc751892MEDIUM

Information Disclosure in Google Sheets Plugin in Grafana

Sep 19, 2023
apollographqlllm-apollographql-400a9b4e68bf02faMEDIUM

Information Disclosure in Google Sheets Plugin in Grafana

Sep 19, 2023
jenkinsllm-jenkins-6bce5cf61c4fc232MEDIUM

Information Disclosure in Google Sheets Plugin in Grafana

Sep 19, 2023
nodejsllm-nodejs-2c08e67718756155MEDIUM

Information Disclosure in Google Sheets Plugin in Grafana

Sep 19, 2023

References

grafana.com / security/security-advisories/cve-2023-4457
Vendor Advisory