PT-2020-8637 · Grafana · Grafana

Noasand

·

Published

2020-06-02

·

Updated

2024-08-21

·

CVE-2018-18623

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Grafana version 5.3.1
Description: The issue is related to an incomplete fix, resulting in a XSS vulnerability via the "Dashboard > Text Panel" screen. This allows for potential exploitation.
Recommendations: For Grafana version 5.3.1, consider disabling the Text Panel feature in the Dashboard as a temporary workaround until a patch is available. Restrict access to the Dashboard to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-18623
ECHO-AB16-2279-8266
GHSA-CMQ2-J8V8-2Q44
GO-2022-0342
RHSA-2019:0019
SUSE-SU-2020:2876-1
SUSE-SU-2020:2911-1
SUSE-SU-2020:3309-1
SUSE-SU-2021:1233-1
SUSE-SU-2021:1962-1

Affected Products

Grafana