CVE-2015-9282: XSS
Published Feb 6, 2019
·Updated
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.
Affected Software
1 affected component
Grafana Piechart-panel Grafana<=1.3.4
Remediation
Patch Available
Event History
Feb 6, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9282?
CVE-2015-9282 is classified as a medium severity vulnerability due to its potential for remote XSS attacks.
2
How do I fix CVE-2015-9282?
To fix CVE-2015-9282, update the Pie Chart Panel plugin to a version later than 1.3.4.
3
What type of vulnerability is CVE-2015-9282?
CVE-2015-9282 is a cross-site scripting (XSS) vulnerability.
4
What can an attacker do with CVE-2015-9282?
An attacker can exploit CVE-2015-9282 to gain remote unauthenticated access to a Grafana dashboard.
5
Which versions of Grafana are affected by CVE-2015-9282?
Grafana versions using the Pie Chart Panel plugin up to and including version 1.3.4 are affected by CVE-2015-9282.