First published: Tue May 08 2018(Updated: )
A flaw was found in Grafana before 5.2.0-beta1 has cross-site scripting vulnerabilities in the dashboard links when using html with XSS as a link title. References: <a href="https://github.com/grafana/grafana/pull/11813">https://github.com/grafana/grafana/pull/11813</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ceph | <2:12.2.8-128.el7c | 2:12.2.8-128.el7c |
redhat/ceph-ansible | <0:3.2.15-1.el7c | 0:3.2.15-1.el7c |
redhat/grafana | <0:5.2.4-2.el7c | 0:5.2.4-2.el7c |
redhat/grafana | <5.2.0 | 5.2.0 |
Grafana Grafana | <=5.1.3 | |
Netapp Active Iq Performance Analytics Services | ||
Netapp Storagegrid Webscale Nas Bridge | ||
go/github.com/grafana/grafana | <5.2.0-beta1 | 5.2.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12099 is a vulnerability in Grafana before 5.2.0-beta1 that allows for XSS (cross-site scripting) attacks through dashboard links.
CVE-2018-12099 has a severity rating of 6.8 (medium).
The following software versions are affected by CVE-2018-12099: Grafana before 5.2.0-beta1.
To fix CVE-2018-12099, upgrade to Grafana version 5.2.0-beta1 or later.
XSS (cross-site scripting) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.