CVE-2018-18624: XSS
A flaw was found in grafana. An incomplete fix for CVE-2018-12099 allows for a XSS via a column style on the "Dashboard > Table Panel" screen.
Other sources
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
Grafana has a XSS vulnerability via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
— GitHub
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-18624?
CVE-2018-18624 is classified as a critical vulnerability due to its potential for cross-site scripting (XSS).
How do I fix CVE-2018-18624?
To fix CVE-2018-18624, upgrade Grafana to version 6.7.4 or later, or 7.0.0 or later.
Which versions of Grafana are affected by CVE-2018-18624?
CVE-2018-18624 affects Grafana version 5.3.1 and earlier, as well as versions up to 6.7.3 and 7.0.0.
What type of attack does CVE-2018-18624 allow?
CVE-2018-18624 allows for cross-site scripting (XSS) attacks via a column style on the Dashboard > Table Panel screen.
Is there a known workaround for CVE-2018-18624?
No specific workaround is available for CVE-2018-18624; updating to a patched version is recommended.