Company
Date Published
Author
Leandro Deveikis
Word count
565
Language
English
Hacker News points
None

Summary

Grafana Labs released Grafana Image Renderer v3.8.3 to address a high-severity vulnerability, CVE-2023-4863, which allowed remote attackers to perform an out-of-bounds memory write via a crafted HTML page due to a flaw in the libwebp library used by Google Chrome. This vulnerability impacted all versions of Grafana running the Image Renderer plugin v3.8.2 or earlier, as the service uses Chrome for rendering dashboards. The issue was discovered after Google released a Chrome update addressing the flaw, and the Grafana team quickly implemented a fix in version 3.8.3, which was promptly deployed to Grafana Cloud. Grafana Labs ensured that cloud providers offering Grafana Cloud Pro were notified under embargo and confirmed their services' security. Customers were advised to upgrade to the latest version, and Grafana Labs emphasized responsible disclosure practices, requesting that vulnerabilities not be disclosed publicly until a fix is available and announced.