ALT-PU-2019-2257-1
Closed vulnerabilities
Published: 2019-06-30
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-13068
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
Severity: MEDIUM (5.4)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References:
- http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
- http://packetstormsecurity.com/files/171500/Grafana-6.2.4-HTML-Injection.html
- https://github.com/grafana/grafana/issues/17718
- https://github.com/grafana/grafana/issues/17718
- https://github.com/grafana/grafana/releases/tag/v6.2.5
- https://github.com/grafana/grafana/releases/tag/v6.2.5
- https://security.netapp.com/advisory/ntap-20190710-0001/
- https://security.netapp.com/advisory/ntap-20190710-0001/