Описание
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
A flaw was found in grafana. The software is vulnerable to an annotation popup XSS.
Отчет
This issue affects the version of the grafana package as shipped with Red Hat Ceph Storage (RHCS) version 2. Ceph-2 has reached End of Extended Life Cycle Support and no longer fixing moderates/lows.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 2 | grafana | Out of support scope | ||
Red Hat Ceph Storage 3 | grafana | Affected | ||
Red Hat Ceph Storage 3 | grafana-container | Affected | ||
Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Affected | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Will not fix | ||
Red Hat Storage 3 | grafana | Affected | ||
OpenShift Service Mesh 1.0 | servicemesh-grafana | Fixed | RHSA-2020:2861 | 07.07.2020 |
OpenShift Service Mesh 1.1 | servicemesh-grafana | Fixed | RHSA-2020:2796 | 01.07.2020 |
Red Hat Enterprise Linux 8 | grafana | Fixed | RHSA-2020:4682 | 04.11.2020 |
Red Hat OpenShift Container Platform 4.6 | openshift4/ose-grafana | Fixed | RHSA-2020:4298 | 27.10.2020 |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1848089grafana: XSS annotation popup vulnerability
6.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 5 лет назад
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVSS3: 6.1
nvd
больше 5 лет назад
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
CVSS3: 6.1
debian
больше 5 лет назад
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
github
около 3 лет назад
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
oracle-oval
больше 4 лет назад
ELSA-2020-4682: grafana security, bug fix, and enhancement update (MODERATE)
6.1 Medium
CVSS3