@grafana/data@7.2.0-pre.0-43ef052d57 vulnerabilities

Grafana Data Library

Direct Vulnerabilities

Known vulnerabilities in the @grafana/data package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cross-site Scripting (XSS)

@grafana/data is a This package holds the root data types and functions used within Grafana.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when an attacker convince a victim to visit a URL referencing a vulnerable page. The URL is not validated and the AngularJS rendering engine will execute the JavaScript expression contained in the URL.

How to fix Cross-site Scripting (XSS)?

Upgrade @grafana/data to version 8.2.3 or higher.