First published: Mon Apr 27 2020(Updated: )
A flaw was found in grafana. The software is vulnerable to an annotation popup XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <6.7.3 | 6.7.3 |
redhat/servicemesh-grafana | <0:6.2.2-38.el8 | 0:6.2.2-38.el8 |
redhat/servicemesh-grafana | <0:6.4.3-11.el8 | 0:6.4.3-11.el8 |
redhat/grafana | <0:6.7.4-3.el8 | 0:6.7.4-3.el8 |
Grafana Grafana | <6.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-12052 is a vulnerability in Grafana version < 6.7.3 that allows for annotation popup XSS.
CVE-2020-12052 has a severity rating of 6.1 (medium).
Grafana versions < 6.7.3 are affected by CVE-2020-12052.
To fix CVE-2020-12052, update Grafana to version 6.7.3 or higher.
You can find more information about CVE-2020-12052 at the following references: [link1], [link2], [link3].