GHSA-37x5-qpm8-53rq

    Dashboard / Vulnerabilities / GHSA-37x5-qpm8-53rq

    GHSA-37x5-qpm8-53rq

    Published: 16 Oct 2023Last Modified: 20 May 2024

    Summary: Google Sheets data source plugin for Grafana information disclosure vulnerability

    Details: Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source. This vulnerability was fixed in version 1.2.2.

    Affected packages

    Package

    Name: github.com/grafana/google-sheets-datasource

    Purl: pkg:golang/github.com/grafana/google-sheets-datasource

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.9.0
    Fixed -1.2.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-37x5-qpm8-53rq | CVE-DB