CVE-2019-13068
MEDIUM5.4EPSS 4.8%Grafana Cross-site Scripting vulnerability
發布日:2022/5/24修改日:2023/11/8
描述
`public/app/features/panel/panel_ctrl.ts` in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
受影響套件(1)
- Go/github.com/grafana/grafanafrom 0, < 6.2.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-13068
- PATCHhttps://github.com/grafana/grafana
- WEBhttp://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
- WEBhttps://github.com/grafana/grafana/issues/17718
- WEBhttps://github.com/grafana/grafana/releases/tag/v6.2.5
- WEBhttps://security.netapp.com/advisory/ntap-20190710-0001