PT-2022-28044 · Unknown+2 · Graphite Web+2

Risicle

·

Published

2022-12-24

·

Updated

2023-08-09

·

CVE-2022-4730

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Graphite Web (affected versions not specified)
Description A problem was found in Graphite Web. It affects an unknown function of the Absolute Time Range Handler component. The issue leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations Apply a patch to fix this issue. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. As a temporary workaround, consider restricting access to the Absolute Time Range Handler component until a patch is available.

Exploit

Fix

Improper Neutralization

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-4730
DLA-3309-1
GHSA-M973-4VPC-X43C
USN-6243-1
USN-6243-2

Affected Products

Graphite Web
Linuxmint
Ubuntu