Bug 1172128 - (CVE-2020-13430) VUL-0: CVE-2020-13430: grafana: XSS via the OpenTSDB datasource.
(CVE-2020-13430)
VUL-0: CVE-2020-13430: grafana: XSS via the OpenTSDB datasource.
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/260000/
CVSSv3.1:SUSE:CVE-2020-13430:6.4:(AV:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-05-26 12:54 UTC by Alexandros Toptsoglou
Modified: 2020-08-04 07:29 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Alexandros Toptsoglou 2020-05-26 12:56:06 UTC
All our codestreams seem affected. Specifically: 

Cloud 7,8,9
SES 5,6 
SLE12
Comment 2 Patrick Seidensal 2020-05-26 14:18:04 UTC
Is this still relevant for SES when we do not need, provide nor support TSDB as data source?
Comment 3 Alexandros Toptsoglou 2020-05-26 14:19:52 UTC
(In reply to Patrick Seidensal from comment #2)
> Is this still relevant for SES when we do not need, provide nor support TSDB
> as data source?

If we do not provide it then no. I will adjust the tracking
Comment 4 Alexandros Toptsoglou 2020-05-26 14:20:48 UTC
(In reply to Alexandros Toptsoglou from comment #1)
> All our codestreams seem affected. Specifically: 
> 
> Cloud 7,8,9
> SES 5,6 
> SLE12

+ SLE15
Comment 5 Flávio Ramalho 2020-05-29 18:09:23 UTC
Cloud also does not need, provide nor support OpenTSDB as data source.

Assigning it back to the security team.
Comment 6 Alexandros Toptsoglou 2020-08-04 07:29:03 UTC
SLE12 and SLE15 are in 7.0.3  version which is an already fixed version storage and cloud products do not need, provide nor support OpenTSDB as data source. Closing