Логотип exploitDog
bind:CVE-2025-41117
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-41117

Количество 6

Количество 6

ubuntu логотип

CVE-2025-41117

около 1 месяца назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
redhat логотип

CVE-2025-41117

около 1 месяца назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-41117

около 1 месяца назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2025-41117

около 1 месяца назад

Stack traces in Grafana's Explore Traces view can be rendered as raw H ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-cqp7-wf4c-3xgc

около 1 месяца назад

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2026-02010

около 1 месяца назад

Уязвимость компонента Explore Traces платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw H ...

CVSS3: 6.8
0%
Низкий
около 1 месяца назад
github логотип
GHSA-cqp7-wf4c-3xgc

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

CVSS3: 6.8
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-02010

Уязвимость компонента Explore Traces платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю выполнить произвольный JavaScript-код

CVSS3: 6.8
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу