- Description
- Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.
- Source
- security-advisories@github.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 8.7
- Impact score
- 5.8
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Severity
- HIGH
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38231605-A82E-4D32-893D-69A2FE01F808",
"versionEndExcluding": "8.3.10",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5136FB0-D7F8-4BDD-9C70-CB2648065A1F",
"versionEndExcluding": "8.4.10",
"versionStartIncluding": "8.4.0"
},
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C2FAADE-D9EA-431C-ACFA-9F846F14B5A2",
"versionEndExcluding": "8.5.9",
"versionStartIncluding": "8.5.0"
},
{
"criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A29E8B3E-D3A9-49A4-ABCD-4E87F8B527DD",
"versionEndExcluding": "9.0.3",
"versionStartIncluding": "9.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24B8DB06-590A-4008-B0AB-FCD1401C77C6"
}
],
"operator": "OR"
}
]
}
]