• 公告ID (KylinSec-SA-2024-1588)

摘要:

A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216744.

安全等级: Low

公告ID: KylinSec-SA-2024-1588

发布日期: 2024年5月27日

关联CVE: CVE-2022-4730  

  • 详细介绍

1. 漏洞描述

   

A vulnerability was found in Graphite Web. It has been classified as problematic. Affected is an unknown function of the component Absolute Time Range Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 2f178f490e10efc03cd1d27c72f64ecab224eb23. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216744.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2022-4730 KY3.4-4A graphite2 Unaffected
CVE-2022-4730 KY3.4-5 graphite2 Unaffected
CVE-2022-4730 KY3.5.1 graphite2 Unaffected
CVE-2022-4730 KY3.5.2 graphite2 Unaffected
CVE-2022-4730 V6 graphite2 Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-1587 下一篇:KylinSec-SA-2024-1589