Vulnerabilities/

XSS vulnerability allowing arbitrary JavaScript execution

Severity:
Medium

Description

Today we are releasing Grafana 8.2.3. This patch release includes an important security fix for an issue that affects all Grafana versions from 8.0.0-beta1.

Grafana Cloud instances have already been patched and an audit did not find any usage of this attack vector. Grafana Enterprise customers were provided with updated binaries under embargo.

Recommendation

Update the @grafana/data package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@grafana/data
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing