PT-2022-6560 · Grafana+7 · Grafana+7
Jasu Vindig
·
Published
2022-01-21
·
Updated
2025-09-29
·
CVE-2022-21702
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana (affected versions not specified)
Description
The issue allows an attacker to serve HTML content through the Grafana datasource or plugin proxy, tricking a user into visiting a specially crafted HTML page and executing a Cross-site Scripting (XSS) attack. This can be done by compromising an existing datasource or setting up a public service and instructing users to set it up in their Grafana instance. The attacker must be in control of the HTTP server serving the URL of the datasource or plugin and have a specially crafted link clicked on by an authenticated user. There are no known workarounds for this issue.
Recommendations
Update to a patched version.
As a temporary workaround, consider restricting access to the
datasource and plugin proxies until a patch is available.
Avoid using specially crafted links that point to attacker-controlled datasources or plugins until the issue is resolved.
Restrict access to compromised plugins to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Grafana
Red Hat
Red Os
Rocky Linux
Suse