CVE-2026-21722
Public Dashboards time range restriction on annotations can be bypassed
5.3
MEDIUM
CVSS 3.1
EPSS 0.33%
描述
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.
如何修補 CVE-2026-21722
要修補 CVE-2026-21722,請將受影響套件升級到下列已修補版本。
- —升級至 11.6.10 或更新版本
CVE-2026-21722 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 9.3.0, < 11.6.10, >= 12.0.0, < 12.1.6, >= 12.2.0, < 12.2.4, >= 12.3.0, < 12.3.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |