Google Sheets data source plugin for Grafana information disclosure vulnerability
Moderate severity
GitHub Reviewed
Published
Oct 16, 2023
to the GitHub Advisory Database
•
Updated May 20, 2024
Package
Affected versions
>= 0.9.0, < 1.2.2
Patched versions
1.2.2
Description
Published by the National Vulnerability Database
Oct 16, 2023
Published to the GitHub Advisory Database
Oct 16, 2023
Reviewed
Oct 20, 2023
Last updated
May 20, 2024
Grafana is an open-source platform for monitoring and observability.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability.
The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is configured for the data source.
This vulnerability was fixed in version 1.2.2.
References