The vendor explicitly identifies these products or versions as containing the fix.
- grafana12-4-main@aarch64 as a component of Red Hat Hardened Images
- grafana12-4-main@src as a component of Red Hat Hardened Images
- grafana12-4-main@x86_64 as a component of Red Hat Hardened Images
- grafana13-1-main@aarch64 as a component of Red Hat Hardened Images
- grafana13-1-main@src as a component of Red Hat Hardened Images
- grafana13-1-main@x86_64 as a component of Red Hat Hardened Images
- grafana13-2-main@aarch64 as a component of Red Hat Hardened Images
- grafana13-2-main@src as a component of Red Hat Hardened Images
- grafana13-2-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw in Grafana allows authenticated 'Editor' users to inject malicious scripts into a table panel's field names. Viewing the compromised dashboard executes the script in the victim's browser, risking data theft or client-side attacks.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
