Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana
Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v7.0.0.
02 / AFFECTED SOFTWARE
Affected packages
45 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v7.0.0.
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
05 / REFERENCES
Further evidence
- https://github.com/grafana/grafana/pull/24539
- https://github.com/grafana/grafana/releases/tag/v7.0.0
- https://security.netapp.com/advisory/ntap-20200528-0003/
- https://github.com/advisories/GHSA-7m2x-qhrq-rp8h
- https://github.com/grafana/grafana
- https://nvd.nist.gov/vuln/detail/CVE-2020-13430
- https://security.netapp.com/advisory/ntap-20200528-0003