RHSA-2020:4682MediumCVSS 6.5
Red Hat Security Advisory: grafana security, bug fix, and enhancement update
🔗 CVE IDs covered (8)
📋 Description
CVE-2018-18624 — grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen CVE-2019-19499 — grafana: arbitrary file read via MySQL data source CVE-2020-11110 — grafana: stored XSS CVE-2020-12052 — grafana: XSS annotation popup vulnerability CVE-2020-12245 — grafana: XSS via column.title or cellLinkTooltip CVE-2020-12458 — grafana: information disclosure through world-readable /var/lib/grafana/grafana.db CVE-2020-12459 — grafana: information disclosure through world-readable grafana configuration files CVE-2020-13430 — grafana: XSS via the OpenTSDB datasource
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2020:4682
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1807323
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827765
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1829724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848108
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1848643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1850572
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1861044
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1873615
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4682.json