CVE-2023-4457 is an information disclosure vulnerability affecting the Google Sheets data source plugin for Grafana, specifically versions 0.9.0 to 1.2.2. The flaw stems from improper sanitization of error messages, which could inadvertently expose the configured Google Sheet API key. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, posing a significant risk of confidentiality compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.0, <= 1.2.2CPE matchmatch criteria | cpe:2.3:a:grafana:google_sheets:*:*:*:*:*:grafana:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Google Sheets data source plugin for Grafana information disclosure vulnerability
Oct 16, 2023Information Disclosure in Google Sheets Plugin in Grafana
Sep 19, 2023Information Disclosure in Google Sheets Plugin in Grafana
Sep 19, 2023Information Disclosure in Google Sheets Plugin in Grafana
Sep 19, 2023Information Disclosure in Google Sheets Plugin in Grafana
Sep 19, 2023Information Disclosure in Google Sheets Plugin in Grafana
Sep 19, 2023Information Disclosure in Google Sheets Plugin in Grafana
Sep 19, 2023