Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2025-41117

6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2025-41117

6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-41117

6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2025-41117

6 месяцев назад

Stack traces in Grafana's Explore Traces view can be rendered as raw H ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-cqp7-wf4c-3xgc

6 месяцев назад

Grafana has a Cross-site Scripting issue

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2026-02010

6 месяцев назад

Уязвимость компонента Explore Traces платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw H ...

CVSS3: 6.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-cqp7-wf4c-3xgc

Grafana has a Cross-site Scripting issue

CVSS3: 6.8
0%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-02010

Уязвимость компонента Explore Traces платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 6.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу