Description: "Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip." PR: https://github.com/grafana/grafana/pull/23816
@maintainer(s), please create an appropriate ebuild
CVE-2020-12052 (https://nvd.nist.gov/vuln/detail/CVE-2020-12052): Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7308261fd9413cf2fcd60b636f223ad68d7b6f77 commit 7308261fd9413cf2fcd60b636f223ad68d7b6f77 Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-05-11 12:06:42 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-05-11 12:07:25 +0000 www-apps/grafana-bin: security cleanup Bug: https://bugs.gentoo.org/719306 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> www-apps/grafana-bin/Manifest | 2 - www-apps/grafana-bin/grafana-bin-6.5.3.ebuild | 71 --------------------------- www-apps/grafana-bin/grafana-bin-6.7.2.ebuild | 71 --------------------------- 3 files changed, 144 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=57aceac5058d4208590578b1ffff790e62e667aa commit 57aceac5058d4208590578b1ffff790e62e667aa Author: Thomas Deutschmann <whissi@gentoo.org> AuthorDate: 2020-05-11 12:06:19 +0000 Commit: Thomas Deutschmann <whissi@gentoo.org> CommitDate: 2020-05-11 12:07:24 +0000 www-apps/grafana-bin: bump to v6.7.3 Bug: https://bugs.gentoo.org/719306 Package-Manager: Portage-2.3.99, Repoman-2.3.22 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org> www-apps/grafana-bin/Manifest | 1 + www-apps/grafana-bin/grafana-bin-6.7.3.ebuild | 71 +++++++++++++++++++++++++++ 2 files changed, 72 insertions(+)
Repository is clean, all done!