ALT-PU-2019-2257-2
Closed vulnerabilities
Published: 2019-06-30
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-13068
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
Severity: MEDIUM (4.3)Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: MEDIUM (5.4)Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References:
- http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
- https://github.com/grafana/grafana/issues/17718
- https://github.com/grafana/grafana/releases/tag/v6.2.5
- https://security.netapp.com/advisory/ntap-20190710-0001/
- http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
- https://github.com/grafana/grafana/issues/17718
- https://github.com/grafana/grafana/releases/tag/v6.2.5
- https://security.netapp.com/advisory/ntap-20190710-0001/
Published: 2022-05-24
Modified: 2023-03-28
Modified: 2023-03-28
GHSA-7phr-6cc9-4m5q
Grafana Cross-site Scripting vulnerability
Severity: MEDIUM (5.4)Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-13068
- https://github.com/grafana/grafana/issues/17718
- https://github.com/grafana/grafana
- https://github.com/grafana/grafana/releases/tag/v6.2.5
- https://security.netapp.com/advisory/ntap-20190710-0001
- http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
