Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13430

Опубликовано: 24 мая 2020
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

A flaw was found in grafana Tag value XSS via the OpenTSDB datasource are possible. The highest threat from this vulnerability is to data confidentiality and integrity.

Отчет

Red Hat Ceph Storage (RHCS) delivers the affected code of the grafana OpenTSDB plugin. However Red Hat Ceph Storage uses the Prometheus time-series database as a default data source not the OpenTSDB, hence the impact by this vulnerability is set to low. Red Hat Gluster Storage (RHGS) delivers the affected code of the grafana OpenTSDB plugin. However Red Hat Gluster Storage uses the Graphite as a data source not the OpenTSDB, hence the impact by this vulnerability is set to low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2grafanaOut of support scope
Red Hat Ceph Storage 3grafanaAffected
Red Hat Ceph Storage 3grafana-containerAffected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat OpenShift Container Platform 3.11openshift3/grafanaWill not fix
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaWill not fix
Red Hat Storage 3grafanaAffected
OpenShift Service Mesh 1.0servicemesh-grafanaFixedRHSA-2020:286107.07.2020
OpenShift Service Mesh 1.1servicemesh-grafanaFixedRHSA-2020:279601.07.2020
Red Hat Enterprise Linux 8grafanaFixedRHSA-2020:468204.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1848108grafana: XSS via the OpenTSDB datasource

EPSS

Процентиль: 55%
0.00324
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
nvd
около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
debian
около 5 лет назад

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

CVSS3: 6.1
github
около 3 лет назад

Grafana XSS via the OpenTSDB datasource

oracle-oval
больше 4 лет назад

ELSA-2020-4682: grafana security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 55%
0.00324
Низкий

6.1 Medium

CVSS3