Reflected cross-site scripting (XSS) In github.com/grafana/grafana
Description
Grafana XSS via the OpenTSDB datasource Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 7.0.0 | ||
rpm rhel8 | 0:6.7.4-3.el8 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.