/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-r23r-h965-qf53

Published

Last updated

https://images.chainguard.dev/security/CGA-r23r-h965-qf53
Package

grafana-11.4

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2018-20677
  • GHSA-ph58-4vrj-w6hr

Severity

6.1

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2018-20677

Updates

Status

Pending upstream fix

Impact

Grafana project maintainers claim the bootstrap lib is only there now to support Angular plugins that still use them. Angular is planned to be removed as a part of the Grafana 12 release. Until then this library is required. However, since the release of Grafana v11, the angular_support_enabled configuration parameter to inherently support for AngularJS based plugins is set to false by default. The bootstrap vulnerability exposure is entirely controlled by the configuration and use cases determined by the user


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing