Package
grafana-fips-13.0
Component
github.com/prometheus/prometheus
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
GHSA-vffh-x6r8-xx99 is an XSS in Prometheus's React web UI (web/ui/*.tsx). The grafana binary imports github.com/prometheus/prometheus only as a Go library and contains no prometheus/prometheus/web symbols; the vulnerable JavaScript is absent from both the binary and /usr/share/grafana/public/ static assets. Matches FP determination already in place on grafana-fips-{11.6, 12.2, 12.3, 12.4} (precedent CGA IDs: CGA-2424-8563-6x9c, CGA-hh2v-6qg6-ffjp, CGA-pvh8-2v62-w76q, CGA-vfpq-5p8w-4x35, CGA-prx5-5q96-p6cf, CGA-8frv-3837-q93f, CGA-7v56-wxgr-83xj, CGA-8qcc-56f4-j5c7).
Status