Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-24303

Опубликовано: 08 июн. 2020
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

A flaw was found in grafana. A XSS via a query alias for the ElasticSearch datasource is allowed.

Отчет

A vulnerable version of Grafana is shipped in OpenShift 3.11 - 4.5 and OpenShift ServiceMesh, however Prometheus is used as a data source and modification to Elasticsearch or Testdata requires full control of the grafana component. Access is restricted to authenticated users only by OpenShift OAuth. As OpenShift and OpenShift ServiceMesh still packages the vulnerable code, the components are affected but with impact Low. OpenShift 4.6 uses version 7.2.0 of Grafana in openshift4/ose-grafana-container and is not affected. Red Hat Ceph Storage 3 and 4 ship a vulnerable version of grafana, however, Prometheus is used as the data source., and thus the impact is rated as low. Red Hat Gluster Storage 3 ships vulnerable version of grafana, however Graphite is the only supported data source and hence this issue has been rated as having a security impact of Low.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1servicemesh-grafanaFix deferred
OpenShift Service Mesh 2.0servicemesh-grafanaWill not fix
Red Hat Ceph Storage 2grafanaOut of support scope
Red Hat Ceph Storage 3grafanaAffected
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Affected
Red Hat OpenShift Container Platform 3.11openshift3/grafanaNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-grafanaNot affected
Red Hat Storage 3grafanaAffected
Red Hat Enterprise Linux 8grafanaFixedRHSA-2021:185918.05.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1892418grafana: XSS via a query alias for the Elasticsearch and Testdata datasource

EPSS

Процентиль: 73%
0.00816
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 4 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
nvd
больше 4 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS3: 6.1
debian
больше 4 лет назад

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the Elast ...

CVSS3: 6.1
github
около 3 лет назад

Grafana XSS via a query alias for the ElasticSearch datasource

oracle-oval
около 4 лет назад

ELSA-2021-1859: grafana security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 73%
0.00816
Низкий

6.1 Medium

CVSS3