Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9029

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

A flaw was found in the Grafana geomap panel's XYZ tile layer. An attacker with editor privileges can exploit a sanitize-then-interpolate ordering bug by setting a textbox variable's default value to a Cross-Site Scripting (XSS) payload. This payload executes for every user who opens the dashboard, potentially leading to arbitrary code execution and information disclosure.

Отчет

An authenticated attacker with Editor privileges can inject an XSS payload into Grafana's geomap panel to compromise dashboard viewers. Red Hat products do not ship the affected version and are not impacted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4grafana-infinity-datasource-npmNot affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp2/3scale-operator-bundleAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Not affected
Red Hat Ceph Storage 4rhceph/grafana-rhel9Not affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Not affected
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Not affected
Red Hat Ceph Storage 7rhceph/grafana-rhel9Not affected
Red Hat Ceph Storage 8rhceph/grafana-rhel9Not affected
Red Hat Ceph Storage 9rhceph/grafana-rhel10Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2491346grafana: Grafana: Arbitrary code execution and information disclosure via Cross-Site Scripting in geomap panel

EPSS

Процентиль: 17%
0.00251
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 1 месяца назад

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
nvd
около 1 месяца назад

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
debian
около 1 месяца назад

A user with Editor permissions can place a malicious script in the att ...

CVSS3: 5.4
redos
17 дней назад

Уязвимость grafana

CVSS3: 7.3
github
около 1 месяца назад

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTemplateSrv().replace() substitutes the variable value, which uses the glob format with no HTML escaping. The result is passed to OpenLayers via element.innerHTML. An Editor can set a textbox variable's default value to an XSS payload that executes for every user who opens the dashboard. This is a bypass of the CVE-2023-0507 fix

EPSS

Процентиль: 17%
0.00251
Низкий

7.3 High

CVSS3