Grafana stored XSS in github.com/grafana/grafana
Grafana stored XSS in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v6.7.2.
02 / AFFECTED SOFTWARE
Affected packages
47 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
Grafana stored XSS in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v6.7.2.
Grafana through 6.7.1 allows stored XSS.
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.
05 / REFERENCES
Further evidence
- https://github.com/grafana/grafana/blob/master/CHANGELOG.md
- https://security.netapp.com/advisory/ntap-20200810-0002/
- https://github.com/advisories/GHSA-xr3x-62qw-vc4w
- https://github.com/grafana/grafana/commit/fb114a75241aaef4c08581b42509c750738b768a
- https://github.com/grafana/grafana/pull/23254
- https://nvd.nist.gov/vuln/detail/CVE-2020-11110
- https://security.netapp.com/advisory/ntap-20200810-0002
- https://github.com/grafana/grafana