First published: Sun May 24 2020(Updated: )
A flaw was found in grafana Tag value XSS via the OpenTSDB datasource are possible. The highest threat from this vulnerability is to data confidentiality and integrity.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/servicemesh-grafana | <0:6.2.2-38.el8 | 0:6.2.2-38.el8 |
redhat/servicemesh-grafana | <0:6.4.3-11.el8 | 0:6.4.3-11.el8 |
redhat/grafana | <0:6.7.4-3.el8 | 0:6.7.4-3.el8 |
Grafana Grafana | <7.0.0 | |
redhat/grafana | <7.0.0 | 7.0.0 |
go/github.com/grafana/grafana | <7.0.0 | 7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-13430 is a vulnerability in Grafana before 7.0.0 that allows tag value XSS via the OpenTSDB datasource.
The highest threat from CVE-2020-13430 is to data confidentiality and integrity.
To fix CVE-2020-13430, update Grafana to version 7.0.0 or later.
You can find more information about CVE-2020-13430 on the following references: [link1], [link2], [link3].
The Common Weakness Enumeration (CWE) for CVE-2020-13430 is CWE-79 (Cross-site Scripting).