Описание
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 2 | grafana | Affected | ||
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | grafana | Not affected | ||
Red Hat OpenStack Platform 8 (Liberty) Operational Tools | grafana | Not affected | ||
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | grafana | Not affected | ||
Red Hat Storage 3 | grafana | Affected | ||
Red Hat Ceph Storage 3.2 | ceph | Fixed | RHSA-2019:0911 | 30.04.2019 |
Red Hat Ceph Storage 3.2 | ceph-ansible | Fixed | RHSA-2019:0911 | 30.04.2019 |
Red Hat Ceph Storage 3.2 | grafana | Fixed | RHSA-2019:0911 | 30.04.2019 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1590017grafana: Cross-site Scripting (XSS) in dashboard links
6.8 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 7 лет назад
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
CVSS3: 6.1
nvd
около 7 лет назад
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
CVSS3: 6.1
debian
около 7 лет назад
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
6.8 Medium
CVSS3