Lucene search

K
freebsdFreeBSD6DCCC186-B824-11ED-B695-6C3BE5272ACD
HistoryJan 01, 2023 - 12:00 a.m.

Grafana -- Stored XSS in text panel plugin

2023-01-0100:00:00
vuxml.freebsd.org
17
grafana
xss
vulnerability
text plugin
stored xss
react
cvss
medium

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

64.5%

Grafana Labs reports:

During an internal audit of Grafana on January 1, a member of the security
team found a stored XSS vulnerability affecting the core text plugin.
The stored XSS vulnerability requires several user interactions in order
to be fully exploited. The vulnerability was possible due to React’s render
cycle that will pass through the unsanitized HTML code, but in the next cycle,
the HTML is cleaned up and saved in Grafana’s database.
The CVSS score for this vulnerability is 6.4 Medium
(CVSS:6.4/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchgrafana=Β 9.2.0UNKNOWN
FreeBSDanynoarchgrafana<Β 9.2.10UNKNOWN
FreeBSDanynoarchgrafana9=Β 9.2.0UNKNOWN
FreeBSDanynoarchgrafana9<Β 9.2.10UNKNOWN

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

0.002 Low

EPSS

Percentile

64.5%