Cross-Site Scripting Vulnerability in Grafana Pie Chart Panel Plugin
CVE-2020-13429

5.4MEDIUM

Key Information:

Vendor
Grafana
Vendor
CVE Published:
24 May 2020

Summary

The Pie Chart Panel plugin for Grafana, prior to version 1.5.0, contains a cross-site scripting (XSS) vulnerability that can be exploited via the Values Header option, also known as the legend header. This security flaw may allow attackers to inject malicious scripts into the output displayed to users, potentially compromising sensitive information or user interactions. Users are advised to update to the latest version to mitigate this risk and ensure the security of their Grafana environments.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.