/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-553h-4jjh-4w4v

Published

Last updated

https://images.chainguard.dev/security/CGA-553h-4jjh-4w4v
Package

grafana-fips-11.5

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2018-14042
  • GHSA-7mvr-5x2g-wfc8

Severity

6.1

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2018-14042

Updates

Status

Pending upstream fix

Impact

The bootstrap library is included to support deprecated Angular plugins. The default configuration for 11.x disables Angular plugins (https://github.com/grafana/grafana/blob/v11.0.x/conf/defaults.ini#L388-L389), so this code is only used if the user opts-in. Angular support is dropped entirely in 12.x, resolving this vulnerability.


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing