PT-2020-13536 · Grafana+4 · Grafana+4

Published

2020-05-24

·

Updated

2024-06-28

·

CVE-2020-13430

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 7.0.0
Description The issue allows tag value XSS via the OpenTSDB datasource. This can be exploited in Grafana, potentially affecting devices that use the OpenTSDB datasource. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 7.0.0, update to version 7.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the OpenTSDB datasource to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4682
ALT-PU-2020-2045
ALT-PU-2020-2204
BIT-GRAFANA-2020-13430
CESA-2020_4682
CVE-2020-13430
ECHO-2387-CB23-DD37
GHSA-7M2X-QHRQ-RP8H
GO-2024-2515
RHSA-2020:2796
RHSA-2020:2861
RHSA-2020:4682
RHSA-2020_4682

Affected Products

Alt Linux
Almalinux
Centos
Grafana
Red Hat