PT-2022-6560 · Grafana+7 · Grafana+7

Jasu Vindig

·

Published

2022-01-21

·

Updated

2025-09-29

·

CVE-2022-21702

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana (affected versions not specified)
Description The issue allows an attacker to serve HTML content through the Grafana datasource or plugin proxy, tricking a user into visiting a specially crafted HTML page and executing a Cross-site Scripting (XSS) attack. This can be done by compromising an existing datasource or setting up a public service and instructing users to set it up in their Grafana instance. The attacker must be in control of the HTTP server serving the URL of the datasource or plugin and have a specially crafted link clicked on by an authenticated user. There are no known workarounds for this issue.
Recommendations Update to a patched version. As a temporary workaround, consider restricting access to the datasource and plugin proxies until a patch is available. Avoid using specially crafted links that point to attacker-controlled datasources or plugins until the issue is resolved. Restrict access to compromised plugins to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7519
ALSA-2022:8057
ALSA-2025_16880
ALT-PU-2022-1806
ALT-PU-2022-1820
ALT-PU-2023-4567
BDU:2023-02415
BIT-GRAFANA-2022-21702
CESA-2022_7519
CVE-2022-21702
GHSA-XC3P-28HW-Q24G
OESA-2022-1599
OESA-2022-2077
OPENSUSE-SU-2022_1396-1
OPENSUSE-SU-2022_3765-1
OPENSUSE-SU-2024:11836-1
RHSA-2022:7519
RHSA-2022:8057
RHSA-2022_7519
RHSA-2022_8057
RLSA-2022:7519
RLSA-2022:8057
SUSE-FU-2022:1419-1
SUSE-SU-2022:0751-1
SUSE-SU-2022:1396-1
SUSE-SU-2022:2134-1
SUSE-SU-2022:3676-1
SUSE-SU-2022:3765-1
SUSE-SU-2022_3765-1
SUSE-SU-2024:0191-1

Affected Products

Alt Linux
Almalinux
Centos
Grafana
Red Hat
Red Os
Rocky Linux
Suse