First published: Tue Jun 02 2020(Updated: )
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Grafana Grafana | =5.3.1 | |
go/github.com/grafana/grafana | <6.0.0-beta1 | 6.0.0-beta1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18625 is a vulnerability in Grafana 5.3.1 that allows for cross-site scripting (XSS) via a link on the Dashboard > All Panels > General screen.
CVE-2018-18625 has a severity level of medium.
CVE-2018-18625 affects Grafana 5.3.1 and allows for XSS attacks through a link on the Dashboard > All Panels > General screen.
To fix the CVE-2018-18625 vulnerability, you should update Grafana to the latest version and apply any patches or security updates provided by the vendor.
You can find more information about CVE-2018-18625 at the following references: [Link 1](https://github.com/grafana/grafana/pull/11813), [Link 2](https://security.netapp.com/advisory/ntap-20200608-0008/).