From nobody Sat Apr 01 07:13:02 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4PpSzg1bsJz430Q4; Sat, 1 Apr 2023 07:13:03 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4PpSzg19z5z3kwD; Sat, 1 Apr 2023 07:13:03 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1680333183; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Xw2MBh6fAz8tSb49ANDiDiT9GbNxYtRZZgBj+PCYxOg=; b=gTuvxMft6igy/CEUzOKtePFse99eAyt8TOz8rymeO3u9VMH/XY3wcCzMU9DzjbMjvTIXSu 192dCNQnf5kQosqCLkRZB/r6kSvAPs1JJ0bsDklyIw6uNo2hGFMjZDlJN6lOyMtLNC5NeD 2SPA4hR+qcrxWw2O5Tasi+9btb3c8Uq564l57rpc/HyslFf2hQ3mjnuviaG+piXP3Acluf 4k1DItomDw3/amGvXjdGBMG9Gj6sNX1XaRHoZVwbOl/Cgfi+XNkUiBXAy2dzLOd15owevA mCHASRPwirL12wyz9zPYzfjnAiH2OTwOOYTW/ijGve2NlBcWJBCB+ZV2pSu06w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1680333183; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Xw2MBh6fAz8tSb49ANDiDiT9GbNxYtRZZgBj+PCYxOg=; b=HWZSBibh+BdIFpQmU6JWCNbw5ZbdH07EY6P8x+rNRzr4IdixyOL8XaBW/qBeMVUndHOtcZ ClQUPOlt4n6jN/Fxd2qMY1fDUhOh5N2hK/ot5WpZu66o89ruqJj47EmWXU4QwYVUtS6zZb VvvxJ8w6rM2rZMtMuc6oQOJzFWLYljE9f38LCTVRKYi7/6J7Uc33mqyQIhhff8DjNFLxoJ PCnjZkxjLTZ6jEPaCrmDjiKNBs8k1JT/A3ckdYNymJuMVS4gnFdm0kAns++H9NRtnOQQpX LCcAVHG1ougM3PhbmqBpuStHr0sPL76eXwjAZ/h0TYswJCkU3JSm2WXSOUL6TA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1680333183; a=rsa-sha256; cv=none; b=h/IXOXQdLJuGg+dOP8pVD5gMqktq3DW36MeGMZ2AjmSScCm+V8xC1wC1LUSLtL1Rw4r2Qq +3Fu18t+R7ZUlhoYbd7p19Ff8FsjmQlV35QX07GdN9gD/aG7AHtNMwEpiUIChPZjZDlaY7 WwbXWgiVo0klncoZIIUfHeO0gRfMgbW0dVZcqlPJPyCZEoQen+N/JqRD66hGt14XXO3jSw pJ60At5kMj8tm9EHpyo1pwBEiCbmT67bvTTcy/gTz9GhRf832MeQhZK7v6qRcB79cWuqIc IIeGFXw309DMnGhVEa5YLziXFwwGthEySZCgblo4BZEEBn0sH/uqwDOOcxJp5g== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4PpSzf75NHzRcC; Sat, 1 Apr 2023 07:13:02 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 3317D2ds098054; Sat, 1 Apr 2023 07:13:02 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 3317D2K2098053; Sat, 1 Apr 2023 07:13:02 GMT (envelope-from git) Date: Sat, 1 Apr 2023 07:13:02 GMT Message-Id: <202304010713.3317D2K2098053@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Matthew Seaman Subject: git: 686ee0f81612 - main - security/vuxml: document grafana vulnerabilities List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: matthew X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 686ee0f81612ea3ff229b5273314ef1b961cd8c7 Auto-Submitted: auto-generated X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by matthew: URL: https://cgit.FreeBSD.org/ports/commit/?id=686ee0f81612ea3ff229b5273314ef1b961cd8c7 commit 686ee0f81612ea3ff229b5273314ef1b961cd8c7 Author: Matthew Seaman AuthorDate: 2023-04-01 07:02:53 +0000 Commit: Matthew Seaman CommitDate: 2023-04-01 07:12:53 +0000 security/vuxml: document grafana vulnerabilities CVE-2023-1410 PR: 270562 Reported by: Boris Korzun --- security/vuxml/vuln/2023.xml | 51 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) diff --git a/security/vuxml/vuln/2023.xml b/security/vuxml/vuln/2023.xml index edb2e5581b48..1a48698b1d00 100644 --- a/security/vuxml/vuln/2023.xml +++ b/security/vuxml/vuln/2023.xml @@ -283,6 +283,57 @@ + + Grafana -- Stored XSS in Graphite FunctionDescription tooltip + + + grafana + 8.5.22 + 9.0.09.2.15 + 9.3.09.3.11 + 9.4.09.4.7 + + + grafana8 + 8.5.22 + + + grafana9 + 9.2.15 + 9.3.09.3.11 + 9.4.09.4.7 + + + + +

Grafana Labs reports:

+
+

When a user adds a Graphite data source, they can then use the data source + in a dashboard. This capability contains a feature to use Functions. Once + a function is selected, a small tooltip appears when hovering over the name + of the function. This tooltip allows you to delete the selected Function + from your query or show the Function Description. However, no sanitization + is done when adding this description to the DOM.

+

Since it is not uncommon to connect to public data sources, an attacker + could host a Graphite instance with modified Function Descriptions containing + XSS payloads. When the victim uses it in a query and accidentally hovers + over the Function Description, an attacker-controlled XSS payload + will be executed.

+

The severity of this vulnerability is of CVSSv3.1 5.7 Medium + (CVSS: AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N (5.7)).

+
+ +
+ + CVE-2023-1410 + https://grafana.com/security/security-advisories/cve-2023-1410/ + + + 2023-03-14 + 2023-03-29 + +
+ Matrix clients -- Prototype pollution in matrix-js-sdk