The GeoMap and Canvas plugins are core plugins in Grafana, which means that all Grafana instances have GeoMap and Canvas installed. These two plugins are vulnerable to Cross-Site-Scripting where an attacker with an Editor role can add an SVG file containing malicious JavaScript code. When a user with an admin role later edits the GeoMap/Canvas panel, the Javascript is executed.
Created grafana tracking bugs for this issue: Affects: fedora-all [bug 2166183]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6420 https://access.redhat.com/errata/RHSA-2023:6420