Cross-site scripting in Grafana - CVE-2022-21702
Published: June 15, 2022 / Updated: June 16, 2022
Grafana
Grafana Labs
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in Grafana. A remote attacker can trick the victim to visit a specially crafted link, execute arbitrary HTML code, and perform a Cross-site scripting (XSS) attack.
Remediation
External links
- https://github.com/grafana/grafana/security/advisories/GHSA-xc3p-28hw-q24g
- https://grafana.com/blog/2022/02/08/grafana-7.5.15-and-8.3.5-released-with-moderate-severity-security-fixes/
- https://github.com/grafana/grafana/commit/27726868b3d7c613844b55cd209ca93645c99b85
- https://bugzilla.redhat.com/show_bug.cgi?id=2050648