vulnerability

FreeBSD: VID-cecbc674-8b83-11ec-b369-6c3be5272acd (CVE-2022-21702): Grafana -- XSS

Severity
2
CVSS
(AV:N/AC:H/Au:S/C:N/I:P/A:N)
Published
Feb 12, 2022
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

Grafana Labs reports: On Jan. 16, an external security researcher, Jasu Viding contacted Grafana to disclose an XSS vulnerability in the way that Grafana handles data sources. Should an existing data source connected to Grafana be compromised, it could be used to inappropriately gain access to other data sources connected to the same Grafana org. We believe that this vulnerability is rated at CVSS 6.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).

Solutions

freebsd-upgrade-package-grafana6freebsd-upgrade-package-grafana7freebsd-upgrade-package-grafana8
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.