PT-2020-13535 · Grafana+1 · Grafana Piechart-Panel Plugin+1

Simonc6372

·

Published

2020-05-24

·

Updated

2024-06-15

·

CVE-2020-13429

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grafana piechart-panel plugin versions prior to 1.5.0
Description The issue allows for XSS via the Values Header option, also known as the legend header. This is a security concern as it can lead to malicious script execution.
Recommendations For versions prior to 1.5.0, update to version 1.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Values Header option in the piechart-panel plugin to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13429
OPENSUSE-SU-2021:1308-1
OPENSUSE-SU-2021:3175-1
OPENSUSE-SU-2021_1308-1
OPENSUSE-SU-2021_3175-1
OPENSUSE-SU-2024:10819-1
SUSE-SU-2021:3174-1

Affected Products

Grafana Piechart-Panel Plugin
Suse