vulnerability
FreeBSD: VID-cecbc674-8b83-11ec-b369-6c3be5272acd (CVE-2022-21702): Grafana -- XSS
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:N/AC:H/Au:S/C:N/I:P/A:N) | Feb 12, 2022 | Nov 4, 2022 | Dec 10, 2025 |
Severity
2
CVSS
(AV:N/AC:H/Au:S/C:N/I:P/A:N)
Published
Feb 12, 2022
Added
Nov 4, 2022
Modified
Dec 10, 2025
Description
Grafana Labs reports: On Jan. 16, an external security researcher, Jasu Viding contacted Grafana to disclose an XSS vulnerability in the way that Grafana handles data sources. Should an existing data source connected to Grafana be compromised, it could be used to inappropriately gain access to other data sources connected to the same Grafana org. We believe that this vulnerability is rated at CVSS 6.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).
Solutions
freebsd-upgrade-package-grafana6freebsd-upgrade-package-grafana7freebsd-upgrade-package-grafana8
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.