Grafana
cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*
- >= 11.1.0, < 11.6.0+security-01
- >= 11.1.0, < 11.5.3+security-01
- >= 11.1.0, < 11.4.3+security-01
- >= 11.1.0, < 11.3.5+security-01
- >= 11.1.0, < 11.2.8+security-01
A DOM-based cross-site scripting vulnerability has been identified in the built-in XY Chart plugin for Grafana. This issue allows users with Editor permissions to modify a chart panel in a way that executes arbitrary JavaScript. The vulnerability was introduced in Grafana version 11.1.0 and has been addressed in versions 11.6.0+security-01, 11.5.3+security-01, 11.4.3+security-01, 11.3.5+security-01, and 11.2.8+security-01.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject and execute malicious scripts in the context of the user's browser.
Users can upgrade to Grafana versions 11.6.0+security-01, 11.5.3+security-01, 11.4.3+security-01, 11.3.5+security-01, or 11.2.8+security-01 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.