FlawAtlas
Search the atlas
CVE-2020-13430 Moderate

Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana

Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v7.0.0.

Exploit probability 1.8%
Published June 28, 2024
Required by Not available
Last source change June 19, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

45 explicit affected versions

Go github.com/grafana/grafana
Go github.com/grafana/grafana
Bitnami grafana

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

View original source
Open Source Vulnerabilities GHSA-7m2x-qhrq-rp8h

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

View original source
Open Source Vulnerabilities GO-2024-2515

Grafana XSS via the OpenTSDB datasource in github.com/grafana/grafana. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/grafana/grafana before v7.0.0.

View original source
Open Source Vulnerabilities BIT-grafana-2020-13430

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

View original source

05 / REFERENCES

Further evidence