CVE-2018-12099Cross-site Scripting in Grafana Grafana

CWE-79Cross-site Scripting17 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.7%
top 28.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateJun 28

Description

Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Gogithub.com/grafana_grafana< 5.2.0-beta1+1
NVDgrafana/grafana5.1.3

Patches

🔴Vulnerability Details

8
OSV
Grafana Cross-site Scripting (XSS) in github.com/grafana/grafana2024-06-28
GHSA
Grafana Cross-site Scripting (XSS)2024-01-31
OSV
Grafana Cross-site Scripting (XSS)2024-01-31
GHSA
Grafana XSS in Dashboard Text Panel2024-01-30
GHSA
Grafana XSS via adding a link in General feature2024-01-30

📋Vendor Advisories

4
Red Hat
grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen2020-06-02
Red Hat
grafana: XSS vulnerability via the "Dashboard > Text Panel" screen2020-06-02
Red Hat
grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen2020-06-02
Red Hat
grafana: Cross-site Scripting (XSS) in dashboard links2018-05-08

💬Community

4
Bugzilla
CVE-2018-18625 grafana: XSS vulnerability via a link on the "Dashboard > All Panels > General" screen2020-06-24
Bugzilla
CVE-2018-18623 grafana: XSS vulnerability via the "Dashboard > Text Panel" screen2020-06-24
Bugzilla
CVE-2018-18624 grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen2020-06-24
Bugzilla
CVE-2018-12099 grafana: Cross-site Scripting (XSS) in dashboard links2018-06-11
CVE-2018-12099 — Cross-site Scripting | cvebase