CVE-2018-12099: XSS
A flaw was found in Grafana before 5.2.0-beta1 has cross-site scripting vulnerabilities in the dashboard links when using html with XSS as a link title.
References: https://github.com/grafana/grafana/pull/11813
Other sources
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-12099?
CVE-2018-12099 is a vulnerability in Grafana before 5.2.0-beta1 that allows for XSS (cross-site scripting) attacks through dashboard links.
How severe is CVE-2018-12099?
CVE-2018-12099 has a severity rating of 6.8 (medium).
Which software versions are affected by CVE-2018-12099?
The following software versions are affected by CVE-2018-12099: Grafana before 5.2.0-beta1.
How can I fix CVE-2018-12099?
To fix CVE-2018-12099, upgrade to Grafana version 5.2.0-beta1 or later.
What is XSS?
XSS (cross-site scripting) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.