MEDIUM6.1
GHSA-9hv8-4frf-cprf
Grafana XSS via a column style
Quick fix
GHSA-9hv8-4frf-cprf — github.com/grafana/grafana: upgrade to the fixed version with the command below.
go get github.com/grafana/grafana@v7.0.0Details
Grafana has a XSS vulnerability via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/grafana/grafana
Introduced in:
0Fixed in: 7.0.0Fix
go get github.com/grafana/grafana@v7.0.0References
- https://nvd.nist.gov/vuln/detail/CVE-2018-18624[ADVISORY]
- https://github.com/grafana/grafana/pull/11813[WEB]
- https://github.com/grafana/grafana/pull/23816[WEB]
- https://github.com/grafana/grafana/commit/0284747c88eb9435899006d26ffaf65f89dec88e[WEB]
- https://github.com/grafana/grafana[PACKAGE]
- https://security.netapp.com/advisory/ntap-20200608-0008[WEB]