Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11110

Опубликовано: 01 апр. 2020
Источник: redhat
CVSS3: 6.1

Описание

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

A flaw was found in grafana. The lack of URL sanitizing allows for stored XSS.

Отчет

Both OpenShift 3.11 and 4.x grafana-container's package a vulnerable version of grafana. However the grafana instance is set to read-only meaning that the potential XSS attack cannot be performed because the original url field cannot be modified. Access to the grafana panel is additionally behind OpenShift OAuth proxy and requires admin permissions. As OpenShift still packages the vulnerable code, the components are affected but the impact is Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaWill not fix
Red Hat Ceph Storage 2grafanaOut of support scope
Red Hat Ceph Storage 3grafanaAffected
Red Hat Ceph Storage 3grafana-containerAffected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat OpenShift Container Platform 3.11openshift3/grafanaFix deferred
Red Hat Storage 3grafanaAffected
Red Hat Enterprise Linux 8grafanaFixedRHSA-2020:468204.11.2020
Red Hat OpenShift Container Platform 4.6openshift4/ose-grafanaFixedRHSA-2020:429827.10.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVSS3: 5.4
nvd
почти 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVSS3: 5.4
debian
почти 5 лет назад

Grafana through 6.7.1 allows stored XSS due to insufficient input prot ...

CVSS3: 5.4
github
около 3 лет назад

Grafana stored XSS

oracle-oval
больше 4 лет назад

ELSA-2020-4682: grafana security, bug fix, and enhancement update (MODERATE)

6.1 Medium

CVSS3