Cross-site Scripting (XSS) Affecting grafana package, versions <0:7.5.15-3.el9
Threat Intelligence
EPSS
0.18% (56th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS9-GRAFANA-2879778
- published 18 Mar 2022
- disclosed 22 Feb 2022
Introduced: 22 Feb 2022
CVE-2021-23648 Open this link in a new tabHow to fix?
Upgrade Centos:9
grafana
to version 0:7.5.15-3.el9 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream grafana
package and not the grafana
package as distributed by Centos
.
See How to fix?
for Centos:9
relevant fixed versions and status.
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
References
- https://access.redhat.com/security/cve/CVE-2021-23648
- https://access.redhat.com/errata/RHSA-2022:8057
- https://github.com/braintree/sanitize-url/blob/main/src/index.ts%23L11
- https://github.com/braintree/sanitize-url/pull/40
- https://github.com/braintree/sanitize-url/pull/40/commits/e5afda45d9833682b705f73fc2c1265d34832183
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/
- https://snyk.io/vuln/SNYK-JS-BRAINTREESANITIZEURL-2339882
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2PFW6Q2LXXWTFRTMTRN4ZGADFRQPKJ3D/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36GUEPA5TPSC57DZTPYPBL6T7UPQ2FRH/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HLAQRRGNSO5MYCPAXGPH2OCSHOGHSQMQ/
CVSS Scores
version 3.1