CVE-2020-11110
Summary
| CVE | CVE-2020-11110 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-27 13:15:00 UTC |
| Updated | 2023-02-10 18:04:00 UTC |
| Description | Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| grafana/CHANGELOG.md at master · grafana/grafana · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| CVE-2020-11110 Grafana Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 940011 AlmaLinux Security Update for grafana (ALSA-2020:4682)
- 997062 GO (Go) Security Update for github.com/grafana/grafana (GHSA-xr3x-62qw-vc4w)