Количество 12
Количество 12
GHSA-q53q-gxq9-mgrj
Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
CVE-2025-4123
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
CVE-2025-4123
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
CVE-2025-4123
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive.
CVE-2025-4123
A cross-site scripting (XSS) vulnerability exists in Grafana caused by ...
RLSA-2025:7894
Important: grafana security update
RLSA-2025:7892
Important: grafana security update
ELSA-2025-7894
ELSA-2025-7894: grafana security update (IMPORTANT)
ELSA-2025-7893
ELSA-2025-7893: grafana security update (IMPORTANT)
ELSA-2025-7892
ELSA-2025-7892: grafana security update (IMPORTANT)
BDU:2025-06809
Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS)
ROS-20250619-15
Множественные уязвимости grafana
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-q53q-gxq9-mgrj Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin | CVSS3: 7.6 | 15% Средний | 6 месяцев назад | |
CVE-2025-4123 A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive. | CVSS3: 7.6 | 15% Средний | 6 месяцев назад | |
CVE-2025-4123 A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive. | CVSS3: 7.6 | 15% Средний | 6 месяцев назад | |
CVE-2025-4123 A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content-Security-Policy (CSP) in Grafana will block the XSS though the `connect-src` directive. | CVSS3: 7.6 | 15% Средний | 6 месяцев назад | |
CVE-2025-4123 A cross-site scripting (XSS) vulnerability exists in Grafana caused by ... | CVSS3: 7.6 | 15% Средний | 6 месяцев назад | |
RLSA-2025:7894 Important: grafana security update | 15% Средний | 3 месяца назад | ||
RLSA-2025:7892 Important: grafana security update | 15% Средний | около 1 месяца назад | ||
ELSA-2025-7894 ELSA-2025-7894: grafana security update (IMPORTANT) | 6 месяцев назад | |||
ELSA-2025-7893 ELSA-2025-7893: grafana security update (IMPORTANT) | 6 месяцев назад | |||
ELSA-2025-7892 ELSA-2025-7892: grafana security update (IMPORTANT) | 4 месяца назад | |||
BDU:2025-06809 Уязвимость компонента Custom Frontend Plugin платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю осуществлять межсайтовые сценарные атаки (XSS) | CVSS3: 7.6 | 15% Средний | 6 месяцев назад | |
ROS-20250619-15 Множественные уязвимости grafana | CVSS3: 8.3 | 5 месяцев назад |
Уязвимостей на страницу