icon

We found results for “

WS-2020-0412

Good to know:

icon

Date: June 8, 2020

In Grafana, versions v2.5.0 through v7.0.6 are vulnerable to Cross-Site Scripting, due to user input not sanitized properly in the series alias field, and also not escaped when rendered back to the client using typeahead. An attacker can name a series alias with arbitrary javascript code that will be run on a client’s browser.

Language: TYPE_SCRIPT

Severity Score

Severity Score

Weakness Type (CWE)

Cross-Site Scripting (XSS)

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version v7.1.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us