Описание
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
A flaw was found in grafana. A XSS via a query alias for the ElasticSearch datasource is allowed.
Отчет
A vulnerable version of Grafana is shipped in OpenShift 3.11 - 4.5 and OpenShift ServiceMesh, however Prometheus is used as a data source and modification to Elasticsearch or Testdata requires full control of the grafana component. Access is restricted to authenticated users only by OpenShift OAuth. As OpenShift and OpenShift ServiceMesh still packages the vulnerable code, the components are affected but with impact Low. OpenShift 4.6 uses version 7.2.0 of Grafana in openshift4/ose-grafana-container and is not affected. Red Hat Ceph Storage 3 and 4 ship a vulnerable version of grafana, however, Prometheus is used as the data source., and thus the impact is rated as low. Red Hat Gluster Storage 3 ships vulnerable version of grafana, however Graphite is the only supported data source and hence this issue has been rated as having a security impact of Low.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Service Mesh 1 | servicemesh-grafana | Fix deferred | ||
OpenShift Service Mesh 2.0 | servicemesh-grafana | Will not fix | ||
Red Hat Ceph Storage 2 | grafana | Out of support scope | ||
Red Hat Ceph Storage 3 | grafana | Affected | ||
Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Affected | ||
Red Hat OpenShift Container Platform 3.11 | openshift3/grafana | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-grafana | Not affected | ||
Red Hat Storage 3 | grafana | Affected | ||
Red Hat Enterprise Linux 8 | grafana | Fixed | RHSA-2021:1859 | 18.05.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the Elast ...
Grafana XSS via a query alias for the ElasticSearch datasource
ELSA-2021-1859: grafana security, bug fix, and enhancement update (MODERATE)
EPSS
6.1 Medium
CVSS3