CVE-2020-24303: XSS
A flaw was found in grafana. A XSS via a query alias for the ElasticSearch datasource is allowed.
Other sources
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-24303?
CVE-2020-24303 is a vulnerability in Grafana that allows for XSS (Cross-Site Scripting) attacks via a query alias for the ElasticSearch datasource.
How severe is CVE-2020-24303?
CVE-2020-24303 has a severity rating of 6.1 (medium).
How can Grafana versions before 7.1.0-beta 1 be affected by CVE-2020-24303?
Grafana versions before 7.1.0-beta 1 are affected by CVE-2020-24303 if they allow query aliases for the ElasticSearch datasource.
How can I fix CVE-2020-24303?
To fix CVE-2020-24303, ensure that you are using Grafana version 7.1.0-beta 1 or higher.
Where can I find more information about CVE-2020-24303?
You can find more information about CVE-2020-24303 at the following links: [CVE-2020-24303](https://www.cve.org/CVERecord?id=CVE-2020-24303), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-24303), [GitHub Issue](https://github.com/grafana/grafana/pull/25401), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1892418), [Red Hat Advisory](https://access.redhat.com/errata/RHSA-2021:1859).