Red Hat Bugzilla – Bug 1590017
CVE-2018-12099 grafana: Cross-site Scripting (XSS) in dashboard links
Last modified: 2018-06-12 03:23:46 EDT
A flaw was found in Grafana before 5.2.0-beta1 has cross-site scripting vulnerabilities in the dashboard links when using html with XSS as a link title. References: https://github.com/grafana/grafana/pull/11813
The version of Grafana (grafana-2.0.2-3.el7ost) that is shipped in OpenStack Optools (7, 8 & 9) does not contain the vulnerable code or the feature being exploited.