漏洞标题
在Graphite函数描述 tooltip 中存储的XSS
漏洞描述信息
Graphite FunctionDescription工具提示中的存储型XSS
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
漏洞类别
N/A
漏洞标题
Stored XSS in Graphite FunctionDescription tooltip
漏洞描述信息
Grafana is an open-source platform for monitoring and observability.
Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip.
The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized.
An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.
Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:N
漏洞类别
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
漏洞标题
Grafana 跨站脚本漏洞
漏洞描述信息
Grafana是Grafana开源的一套提供可视化监控界面的开源监控工具。该工具主要用于监控和分析Graphite、InfluxDB和Prometheus等。 Grafana 8.5.22之前版本、9.2.15之前版本和 9.3.11之前版本存在跨站脚本漏洞,该漏洞源于函数描述的值没有被正确过滤。
CVSS信息
N/A
漏洞类别
跨站脚本