Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqp7-wf4c-3xgc

Опубликовано: 12 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Grafana has a Cross-site Scripting issue

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.

Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

Пакеты

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

>= 12.2.0, < 12.2.5

12.2.5

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

>= 12.3.0, < 12.3.3

12.3.3

EPSS

Процентиль: 15%
0.00239
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.8
ubuntu
6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
redhat
6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
nvd
6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
debian
6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw H ...

CVSS3: 6.8
fstec
6 месяцев назад

Уязвимость компонента Explore Traces платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный JavaScript-код

EPSS

Процентиль: 15%
0.00239
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-79