@grafana/ui@9.1.0-73368pre vulnerabilities

Grafana Components Library

Direct Vulnerabilities

Known vulnerabilities in the @grafana/ui package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Cross-site Scripting (XSS)

@grafana/ui is a Grafana Components Library

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the core plugin GeoMap, due to SVG-files improper sanitization. Exploiting this vulnerability allowed arbitrary JavaScript to be executed in the context of the currently authorized user of the Grafana instance.

How to fix Cross-site Scripting (XSS)?

Upgrade @grafana/ui to version 8.5.16, 9.3.6 or higher.

>=8.1.0 <8.5.16 >=9.0.0 <9.3.6