Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2025-4123

больше 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Критический
redhat логотип

CVE-2025-4123

больше 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Критический
nvd логотип

CVE-2025-4123

больше 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
EPSS: Критический
debian логотип

CVE-2025-4123

больше 1 года назад

A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...

CVSS3: 7.6
EPSS: Критический
rocky логотип

RLSA-2025:7894

около 1 года назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7893

12 месяцев назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7892

12 месяцев назад

Important: grafana security update

EPSS: Критический
github логотип

GHSA-q53q-gxq9-mgrj

больше 1 года назад

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
EPSS: Критический
oracle-oval логотип

ELSA-2025-7894

больше 1 года назад

ELSA-2025-7894: grafana security update (IMPORTANT)

EPSS: Критический
oracle-oval логотип

ELSA-2025-7893

больше 1 года назад

ELSA-2025-7893: grafana security update (IMPORTANT)

EPSS: Критический
oracle-oval логотип

ELSA-2025-7892

около 1 года назад

ELSA-2025-7892: grafana security update (IMPORTANT)

EPSS: Критический
fstec логотип

BDU:2025-06809

больше 1 года назад

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
EPSS: Критический
redos логотип

ROS-20250619-15

около 1 года назад

Множественные уязвимости grafana

CVSS3: 8.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20654-1

5 месяцев назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
97%
Критический
больше 1 года назад
redhat логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
97%
Критический
больше 1 года назад
nvd логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.

CVSS3: 7.6
97%
Критический
больше 1 года назад
debian логотип
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...

CVSS3: 7.6
97%
Критический
больше 1 года назад
rocky логотип
RLSA-2025:7894

Important: grafana security update

97%
Критический
около 1 года назад
rocky логотип
RLSA-2025:7893

Important: grafana security update

97%
Критический
12 месяцев назад
rocky логотип
RLSA-2025:7892

Important: grafana security update

97%
Критический
12 месяцев назад
github логотип
GHSA-q53q-gxq9-mgrj

Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin

CVSS3: 7.6
97%
Критический
больше 1 года назад
oracle-oval логотип
ELSA-2025-7894

ELSA-2025-7894: grafana security update (IMPORTANT)

97%
Критический
больше 1 года назад
oracle-oval логотип
ELSA-2025-7893

ELSA-2025-7893: grafana security update (IMPORTANT)

97%
Критический
больше 1 года назад
oracle-oval логотип
ELSA-2025-7892

ELSA-2025-7892: grafana security update (IMPORTANT)

97%
Критический
около 1 года назад
fstec логотип
BDU:2025-06809

Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)

CVSS3: 7.6
97%
Критический
больше 1 года назад
redos логотип
ROS-20250619-15

Множественные уязвимости grafana

CVSS3: 8.3
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:20654-1

Security update for grafana

5 месяцев назад

Уязвимостей на страницу