Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade grafana | May 4, 2022 | Oct 28, 2020 |
| Centos_linux | — | Upgrade grafana-debuginfoUpgrade grafana | Jun 1, 2021 | Oct 28, 2020 |
| Oracle_linux | — | Upgrade grafana | May 26, 2021 | Jun 8, 2020 |
| Redhat_linux | — | Upgrade grafanaUpgrade grafana-debuginfo | May 21, 2021 | Oct 28, 2020 |
| Rocky_linux | — | Upgrade grafana-debuginfoUpgrade grafana | Mar 12, 2024 | Oct 28, 2020 |
| Suse | — | Upgrade system-user-grafana | Jun 9, 2021 | Oct 28, 2020 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 28, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub