StackRadar

CVE-2023-3128

Critical

Advisory

Published 22 Jun 2023In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.4
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Grafana vulnerable to Authentication Bypass by Spoofing

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
github.com/grafana/grafanagolangv0.0.0-20230830192226-0cfa76b22dd5, v0.0.0-20231011162216-849c612fcb73, v0.0.0-20231218140301-1e84fede543a, v0.0.0-20250812085420-df5de8219b41+dirty+4 more8.5.27, 9.2.20, 9.3.16, 9.4.139
OSV records
GHSA-mpv3-g8m3-3fjc
Also known as
BIT-grafana-2023-3128, GHSA-gxh2-6vvc-rrgp

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:9.4.71a359d92f40e
github.com/grafana/grafana@v9.4.7
9.4.13

Open the chart page →

17,693
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
github.com/grafana/grafana@v9.4.3
9.4.13

Open the chart page →

17,877
carettagroundcover0.0.161 of 3See more

caretta groundcover 0.0.16

1 of the 3 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/grafana/grafana@v9.3.1
9.3.16

Open the chart page →

6,799
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
github.com/grafana/grafana@v9.2.4
9.2.20

Open the chart page →

30,699
drogue-cloud-metricsdrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
github.com/grafana/grafana@v9.2.4
9.2.20

Open the chart page →

13,558
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
github.com/grafana/grafana@v0.0.0-20231011162216-849c612fcb73
8.5.27

Open the chart page →

7,329
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
8.5.27

Open the chart page →

8,188
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/grafana/grafana@v0.0.0-20230830192226-0cfa76b22dd5
8.5.27

Open the chart page →

3,561
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
github.com/grafana/grafana@v0.0.0-20231218140301-1e84fede543a
8.5.27

Open the chart page →

2,966
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
grafana/grafana:12.1.1a1701c218024
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
8.5.27

Open the chart page →

17,070
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2023-3128.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/grafana/grafana@v9.3.1
9.3.16

Open the chart page →

26,840

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:9.2.4057896e23443
github.com/grafana/grafana@v9.2.4
9.2.20
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/grafana/grafana@v9.3.1
9.3.16
2
grafana/grafana:10.1.50679e877ba20
github.com/grafana/grafana@v0.0.0-20231011162216-849c612fcb73
8.5.27
1
grafana/grafana:9.4.71a359d92f40e
github.com/grafana/grafana@v9.4.7
9.4.13
1
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/grafana/grafana@v0.0.0-20230830192226-0cfa76b22dd5
8.5.27
1
grafana/grafana:10.2.36b5b37eb35bb
github.com/grafana/grafana@v0.0.0-20231218140301-1e84fede543a
8.5.27
1
grafana/grafana:9.4.376dcf36e7d2a
github.com/grafana/grafana@v9.4.3
9.4.13
1
grafana/grafana:12.1.1a1701c218024
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
8.5.27
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
8.5.27
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.