grafana-11.6
Chainguard
6.1
CVSS V3
Status
Impact
The bootstrap library is included to support deprecated Angular plugins. The default configuration for 11.x disables Angular plugins (https://github.com/grafana/grafana/blob/v11.0.x/conf/defaults.ini#L388-L389), so this code is only used if the user opts-in. Angular support is dropped entirely in 12.x, resolving this vulnerability.