CVE-2020-12245: XSS
Published Apr 23, 2020
·Updated
A flaw was found in grafana. A XSS is possible in table-panel via column.title or cellLinkTooltip.
Other sources
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
Affected Software
6 affected componentsFixes available
redhat/servicemesh-grafana<0:6.2.2-38.el8
0:6.2.2-38.el8
redhat/servicemesh-grafana<0:6.4.3-11.el8
0:6.4.3-11.el8
redhat/grafana<0:6.7.4-3.el8
0:6.7.4-3.el8
redhat/grafana<6.7.3
6.7.3
go/github.com/grafana/grafana<6.7.3
6.7.3
Grafana Grafana<6.7.3
Remediation
Patch Available
Event History
Apr 23, 2020
CVE Published
12:00 AM
Apr 24, 2020
CVE Published
via MITRE·08:24 PM
Data Sourced
via MITRE·08:24 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:16 PM
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the severity of CVE-2020-12245?
CVE-2020-12245 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2020-12245?
To fix CVE-2020-12245, upgrade Grafana to version 6.7.3 or later.
3
What versions of Grafana are affected by CVE-2020-12245?
CVE-2020-12245 affects Grafana versions prior to 6.7.3.
4
What components are involved in CVE-2020-12245?
CVE-2020-12245 specifically involves the table-panel through its column.title or cellLinkTooltip.
5
Is there a patch available for CVE-2020-12245?
Yes, the patch for CVE-2020-12245 is included in Grafana version 6.7.3.