VDB
Sign up
MEDIUM6.1

GHSA-9hv8-4frf-cprf

Grafana XSS via a column style

Quick fix

GHSA-9hv8-4frf-cprf — github.com/grafana/grafana: upgrade to the fixed version with the command below.

go get github.com/grafana/grafana@v7.0.0

Details

Grafana has a XSS vulnerability via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/grafana/grafana
Introduced in: 0Fixed in: 7.0.0
Fixgo get github.com/grafana/grafana@v7.0.0

References