CVE-2020-24303Cross-site Scripting in Grafana Grafana

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 40.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateJun 28

Description

Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Gogithub.com/grafana_grafana< 7.1.0-beta1
NVDgrafana/grafana7.0.5

Patches

🔴Vulnerability Details

5
OSV
Grafana XSS via a query alias for the ElasticSearch datasource in github.com/grafana/grafana2024-06-28
OSV
Grafana XSS via a query alias for the ElasticSearch datasource2022-05-24
GHSA
Grafana XSS via a query alias for the ElasticSearch datasource2022-05-24
CVEList
CVE-2020-24303: Grafana before 72020-10-28
OSV
CVE-2020-24303: Grafana before 72020-10-28

📋Vendor Advisories

1
Red Hat
grafana: XSS via a query alias for the Elasticsearch and Testdata datasource2020-06-08

💬Community

2
Bugzilla
CVE-2020-24303 grafana: XSS via a query alias for the Elasticsearch and Testdata datasource2020-10-28
Bugzilla
CVE-2020-24303 grafana: XSS via a query alias for the Elasticsearch and Testdata datasource [fedora-all]2020-10-28
CVE-2020-24303 — Cross-site Scripting | cvebase