PT-2023-8914 · Grafana+1 · Grafana Worldmap Panel Plugin+1

Publicado

2023-10-25

·

Atualizado

2024-05-03

·

CVE-2023-3010

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Grafana WorldMap panel plugin versions prior to 1.0.4
Description The issue is related to a DOM XSS vulnerability in the WorldMap panel plugin of the Grafana platform, which is caused by improper neutralization of input during webpage creation. This can allow a remote attacker to perform cross-site scripting attacks.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider disabling the WorldMap panel plugin until a patch is available. Restrict access to the plugin to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02594
CVE-2023-3010

Produtos afetados

Grafana Worldmap Panel Plugin
Red Os