QID 997070

Date Published: 2024-02-02

QID 997070: GO (Go) Security Update for github.com/grafana/grafana (GHSA-9hv8-4frf-cprf)

Grafana has a XSS vulnerability via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Github security advisory GHSA-9hv8-4frf-cprf for updates and patch information.
    Vendor References

    CVEs related to QID 997070

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9hv8-4frf-cprf github.com/grafana/grafana URL Logo github.com/advisories/GHSA-9hv8-4frf-cprf