[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2020:4682-01 -- Centos grafana

ID: oval:org.secpod.oval:def:67993Date: (C)2020-12-23   (M)2023-03-08
Class: PATCHFamily: unix




Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB amp; OpenTSDB. The following packages have been upgraded to a later upstream version: grafana . Security Fix: * grafana: XSS vulnerability via a column style on the quot;Dashboard gt; Table Panelquot; screen * grafana: arbitrary file read via MySQL data source * grafana: stored XSS * grafana: XSS annotation popup vulnerability * grafana: XSS via column.title or cellLinkTooltip * grafana: information disclosure through world-readable /var/lib/grafana/grafana.db * grafana: information disclosure through world-readable grafana configuration files * grafana: XSS via the OpenTSDB datasource For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the CentOS 8.3 Release Notes linked from the References section.

Platform:
CentOS 8
Product:
grafana
Reference:
RHSA-2020:4682-01
CVE-2018-18624
CVE-2019-19499
CVE-2020-11110
CVE-2020-12052
CVE-2020-12245
CVE-2020-12458
CVE-2020-12459
CVE-2020-13430
CVE    8
CVE-2020-11110
CVE-2020-13430
CVE-2020-12245
CVE-2020-12459
...
CPE    3
cpe:/a:grafana:grafana
cpe:/a:grafana:grafana:5.3.1
cpe:/o:centos:centos:8

© SecPod Technologies