Grafana XSS via adding a link in General feature
Moderate severity
GitHub Reviewed
Published
Jan 30, 2024
to the GitHub Advisory Database
•
Updated Jan 30, 2024
Package
Affected versions
< 6.0.0-beta1
Patched versions
6.0.0-beta1
Description
Published to the GitHub Advisory Database
Jan 30, 2024
Reviewed
Jan 30, 2024
Last updated
Jan 30, 2024
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
References