PT-2020-15676 · Grafana+5 · Grafana+5

Dprokop

·

Published

2020-08-19

·

Updated

2024-06-28

·

CVE-2020-24303

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 7.1.0-beta1
Description The issue allows for XSS via a query alias for the ElasticSearch datasource. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 7.1.0-beta1, update to version 7.1.0-beta1 or later to resolve the issue. As a temporary workaround, consider restricting access to the ElasticSearch datasource to minimize the risk of exploitation. Avoid using query aliases in the ElasticSearch datasource until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2611
ALT-PU-2022-1177
ALT-PU-2022-1249
BIT-GRAFANA-2020-24303
CESA-2021_1859
CVE-2020-24303
ECHO-F629-5DC1-52F5
GHSA-MVPR-Q6RH-8VRP
GO-2024-2520
OESA-2021-1445
RHSA-2021:1859
RHSA-2021_1859
RLSA-2021:1859
SUSE-SU-2020:3624-1
SUSE-SU-2020:3897-1
SUSE-SU-2021:1233-1
SUSE-SU-2021:1962-1

Affected Products

Alt Linux
Centos
Elasticsearch
Grafana
Red Hat
Rocky Linux