Логотип exploitDog
bind:"CVE-2023-1410"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-1410"

Количество 10

Количество 10

ubuntu логотип

CVE-2023-1410

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description. Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2023-1410

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2023-1410

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS3: 6.2
EPSS: Низкий
debian логотип

CVE-2023-1410

больше 2 лет назад

Grafana is an open-source platform for monitoring and observability. ...

CVSS3: 6.2
EPSS: Низкий
github логотип

GHSA-qrrg-gw7w-vp76

больше 2 лет назад

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

CVSS3: 6.2
EPSS: Низкий
fstec логотип

BDU:2024-02575

больше 2 лет назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неправильной нейтрализацией ввода во время создания веб-страницы, позволяющая нарушителю позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1904-1

больше 2 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2575-1

около 2 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2578-1

около 2 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
redos логотип

ROS-20240403-01

больше 1 года назад

Множественные уязвимости grafana

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-1410

Grafana is an open-source platform for monitoring and observability. Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description. Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS3: 6.2
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-1410

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-1410

Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.

CVSS3: 6.2
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-1410

Grafana is an open-source platform for monitoring and observability. ...

CVSS3: 6.2
1%
Низкий
больше 2 лет назад
github логотип
GHSA-qrrg-gw7w-vp76

Grafana Stored Cross-site Scripting in Graphite FunctionDescription tooltip

CVSS3: 6.2
1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02575

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неправильной нейтрализацией ввода во время создания веб-страницы, позволяющая нарушителю позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1904-1

Security update for grafana

больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2575-1

Security update for SUSE Manager Client Tools

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:2578-1

Security update for SUSE Manager Client Tools

около 2 лет назад
redos логотип
ROS-20240403-01

Множественные уязвимости grafana

CVSS3: 9.8
больше 1 года назад

Уязвимостей на страницу