CVE-2020-13429: XSS
Published May 24, 2020
·Updated
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
Affected Software
1 affected component
Grafana Piechart-panel Grafana<1.5.0
Event History
May 24, 2020
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13429?
CVE-2020-13429 is considered a high severity vulnerability due to its potential to allow cross-site scripting (XSS).
2
How do I fix CVE-2020-13429?
To fix CVE-2020-13429, you should upgrade the Pie Chart Panel plugin to version 1.5.0 or later for Grafana.
3
What kind of attack does CVE-2020-13429 facilitate?
CVE-2020-13429 facilitates cross-site scripting (XSS) attacks through the Values Header option in the Pie Chart Panel plugin.
4
Which versions of the Pie Chart Panel are affected by CVE-2020-13429?
Versions of the Pie Chart Panel plugin prior to 1.5.0 are affected by CVE-2020-13429.
5
Is CVE-2020-13429 related to specific software?
Yes, CVE-2020-13429 specifically affects the Pie Chart Panel plugin for Grafana.