Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-98pr-9hw5-crg3

Опубликовано: 15 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01

EPSS

Процентиль: 14%
0.00046
Низкий

7.6 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

nvd
20 дней назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVSS3: 7.6
fstec
20 дней назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

EPSS

Процентиль: 14%
0.00046
Низкий

7.6 High

CVSS3

Дефекты

CWE-601