Bug 1850568 (CVE-2018-18623)
Summary: | CVE-2018-18623 grafana: XSS vulnerability via the "Dashboard > Text Panel" screen | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Michael Kaplan <mkaplan> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | agerstmayr, anpicker, bmontgom, dramseur, eparis, erooth, grafana-maint, hvyas, jburrell, jhunter, jkurik, jokerman, kmitts, lcosic, mcooper, mgala, mgoodwin, mjudeiki, nathans, nstielau, rcernich, sponnaga, surbania |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | grafana 6.0.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in grafana. An incomplete fix for CVE-2018-12099 allows for a XSS in the "Dashboard > Text Panel" screen.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-28 08:23:47 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1850570, 1851999, 1852002, 1852258 | ||
Bug Blocks: | 1850581 |
Description
Michael Kaplan
2020-06-24 13:47:10 UTC
Created grafana tracking bugs for this issue: Affects: fedora-all [bug 1850570] Upstream commit: https://github.com/grafana/grafana/pull/14984/commits/15d560a1c01f5bfb354f83183886881554026bb8 Looks like that is the patch given the comment: https://github.com/grafana/grafana/pull/11813#issuecomment-458045266 The patch got included in the major release of v6.0.0 as well. OpenShift 3.11 grafana-container packages a vulnerable version of grafana 5.4.3, the instance is set to read-only. Meaning the XSS attack cannot be performed as the text panel cannot be modified, or added. As the version still packages the vulnerable code, setting to affected with Low impact. Both OpenShift 4.x and ServiceMesh both package grafana versions greater than 6.0.0 and are not affected. In reply to comment #4: > Both OpenShift 4.x and ServiceMesh both package grafana versions greater > than 6.0.0 and are not affected. Same applies for RHEL-8 -> not affected. upstream PR: https://github.com/grafana/grafana/pull/14984 Statement: While OpenShift 3.11 grafana-container packages a vulnerable version of grafana, the dashboard is set to read-only meaning that the vulnerable component cannot be added or modified to contain the potential XSS. As the OpenShift version still packages vulnerable code, the impact is set Low. External References: https://security.netapp.com/advisory/ntap-20200608-0008/ |