First published: Wed Apr 01 2020(Updated: )
A flaw was found in grafana. The lack of URL sanitizing allows for stored XSS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <0:6.7.4-3.el8 | 0:6.7.4-3.el8 |
redhat/grafana | <6.7.2 | 6.7.2 |
go/github.com/grafana/grafana | <=6.7.1 | 6.7.2 |
Grafana Labs Grafana OSS and Enterprise | <=6.7.1 | |
NetApp E-Series Performance Analyzer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw is CVE-2020-11110.
The severity level of CVE-2020-11110 is medium.
The CWE ID for this vulnerability is CWE-79.
The impact of this vulnerability is stored Cross-Site Scripting (XSS) attacks.
You can mitigate this vulnerability by updating Grafana to version 6.7.2 or later.