PT-2023-8914 · Grafana+1 · Grafana Worldmap Panel Plugin+1
Publicado
2023-10-25
·
Atualizado
2024-05-03
·
CVE-2023-3010
CVSS v3.1
7.3
Alta
| Vetor | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana WorldMap panel plugin versions prior to 1.0.4
Description
The issue is related to a DOM XSS vulnerability in the WorldMap panel plugin of the Grafana platform, which is caused by improper neutralization of input during webpage creation. This can allow a remote attacker to perform cross-site scripting attacks.
Recommendations
For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider disabling the WorldMap panel plugin until a patch is available. Restrict access to the plugin to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Grafana Worldmap Panel Plugin
Red Os