Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr3x-62qw-vc4w

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.4

Описание

Grafana stored XSS

Grafana through 6.7.1 allows stored XSS.

Пакеты

Наименование

github.com/grafana/grafana

go
Затронутые версииВерсия исправления

<= 6.7.1

6.7.2

EPSS

Процентиль: 98%
0.64122
Средний

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVSS3: 6.1
redhat
больше 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVSS3: 5.4
nvd
около 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVSS3: 5.4
debian
около 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input prot ...

oracle-oval
больше 4 лет назад

ELSA-2020-4682: grafana security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 98%
0.64122
Средний

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79