Junglewise Threat Intelligence

CVE-2021-41174: Grafana XSS in AngularJS rendering on unauthenticated pages

CVE-2021-41174 · Severity: low · CVSS 3.1 · Published 2021-11-08

Vendors: npm, Grafana Labs.

Executive brief

Grafana, a popular monitoring and observability platform, is vulnerable to a security flaw that allows attackers to run malicious code in a user's web browser. By tricking an unauthenticated user into clicking a specially crafted link to certain Grafana pages, an attacker could potentially steal session data or display fraudulent login forms. This issue primarily affects organizations using Grafana versions 8.0.0 through 8.2.2.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Grafana versions 8.0.0-beta1 through 8.2.2 due to improper neutralization of input in unauthenticated pages. The vulnerability is rooted in the AngularJS rendering engine's processing of interpolation bindings (double curly braces). When an unauthenticated user visits a crafted URL for specific pages (such as dashboard snapshots or invite links), the login button in the menu bar reflects the malicious URL without validation. This allows an attacker to execute arbitrary JavaScript expressions within the victim's browser context. Exploitation requires user interaction (clicking a link) and affects pages where a login button is present, or all pages if anonymous authentication is enabled. A fix is available in version 8.2.3.

Affected products

  • Grafana Labs Grafana 8.0.0-beta1 to 8.2.2

Timeline

  • 2021-10-21: disclosed: Security researcher reported the vulnerability to Grafana Labs.
  • 2021-10-22: patched: Mitigations and fixes deployed to Grafana Cloud.
  • 2021-10-27: patched: Grafana Enterprise images released to customers under embargo.
  • 2021-11-03: advisory: Public release of the security advisory and patched version 8.2.3.

References