CVE-2020-13430

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in go/github.com/grafana/grafana

Identifiers

GHSA-7m2x-qhrq-rp8h, CVE-2020-13430

Package Slug

go/github.com/grafana/grafana

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.

Affected Versions

All versions before 7.0.0

Solution

Upgrade to version 7.0.0 or above.

Last Modified

2024-02-02

source