{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2018-1000816","title":"Title"},{"category":"description","text":"Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2018-1000816","url":"https://www.suse.com/security/cve/CVE-2018-1000816"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1120791 for CVE-2018-1000816","url":"https://bugzilla.suse.com/1120791"}],"title":"SUSE CVE CVE-2018-1000816","tracking":{"current_release_date":"2025-10-07T09:42:24Z","generator":{"date":"2023-02-15T04:19:52Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2018-1000816","initial_release_date":"2023-02-15T04:19:52Z","revision_history":[{"date":"2023-02-15T04:19:52Z","number":"2","summary":"Current version"},{"date":"2025-01-01T07:08:06Z","number":"3","summary":"Current version"},{"date":"2025-02-15T07:49:54Z","number":"4","summary":"Current version"},{"date":"2025-02-18T06:47:02Z","number":"5","summary":"Current version"},{"date":"2025-03-15T11:42:19Z","number":"6","summary":"Current version"},{"date":"2025-04-08T02:45:29Z","number":"7","summary":"Current version"},{"date":"2025-10-07T09:42:24Z","number":"8","summary":"Current version"}],"status":"interim","version":"8"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Manager Client Tools for SLE 12","product":{"name":"SUSE Manager Client Tools for SLE 12","product_id":"SUSE Manager Client Tools for SLE 12","product_identification_helper":{"cpe":"cpe:/o:suse:sle-manager-tools:12"}}},{"category":"product_name","name":"SUSE Manager Client Tools for SLE 15","product":{"name":"SUSE Manager Client Tools for SLE 15","product_id":"SUSE Manager Client Tools for SLE 15","product_identification_helper":{"cpe":"cpe:/o:suse:sle-manager-tools:15"}}},{"category":"product_name","name":"SUSE Manager Tools 15 SP1","product":{"name":"SUSE Manager Tools 15 SP1","product_id":"SUSE Manager Tools 15 SP1"}},{"category":"product_name","name":"SUSE OpenStack Cloud 7","product":{"name":"SUSE OpenStack Cloud 7","product_id":"SUSE OpenStack Cloud 7","product_identification_helper":{"cpe":"cpe:/o:suse:suse-openstack-cloud:7"}}},{"category":"product_version","name":"grafana","product":{"name":"grafana","product_id":"grafana","product_identification_helper":{"cpe":"cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*","purl":"pkg:rpm/suse/grafana@?upstream=grafana.src.rpm"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"grafana as component of HPE Helion OpenStack 8","product_id":"HPE Helion OpenStack 8:grafana"},"product_reference":"grafana","relates_to_product_reference":"HPE Helion OpenStack 8"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE Enterprise Storage 5","product_id":"SUSE Enterprise Storage 5:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE Enterprise Storage 5"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE Manager Client Tools for SLE 12","product_id":"SUSE Manager Client Tools for SLE 12:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE Manager Client Tools for SLE 12"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE Manager Client Tools for SLE 15","product_id":"SUSE Manager Client Tools for SLE 15:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE Manager Client Tools for SLE 15"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE Manager Tools 15 SP1","product_id":"SUSE Manager Tools 15 SP1:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE Manager Tools 15 SP1"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE OpenStack Cloud 7","product_id":"SUSE OpenStack Cloud 7:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE OpenStack Cloud 7"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE OpenStack Cloud 8","product_id":"SUSE OpenStack Cloud 8:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE OpenStack Cloud 8"},{"category":"default_component_of","full_product_name":{"name":"grafana as component of SUSE OpenStack Cloud Crowbar 8","product_id":"SUSE OpenStack Cloud Crowbar 8:grafana"},"product_reference":"grafana","relates_to_product_reference":"SUSE OpenStack Cloud Crowbar 8"}]},"vulnerabilities":[{"cve":"CVE-2018-1000816","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2018-1000816"}],"notes":[{"category":"general","text":"Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..","title":"CVE description"}],"product_status":{"known_not_affected":["SUSE Manager Client Tools for SLE 12:grafana","SUSE Manager Client Tools for SLE 15:grafana","SUSE Manager Tools 15 SP1:grafana","SUSE OpenStack Cloud 7:grafana"]},"references":[{"category":"external","summary":"CVE-2018-1000816","url":"https://www.suse.com/security/cve/CVE-2018-1000816"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1120791 for CVE-2018-1000816","url":"https://bugzilla.suse.com/1120791"}],"remediations":[{"category":"no_fix_planned","details":"There is no fix planned for these products.\n","product_ids":["HPE Helion OpenStack 8:grafana","SUSE Enterprise Storage 5:grafana","SUSE OpenStack Cloud 8:grafana","SUSE OpenStack Cloud Crowbar 8:grafana"]}],"threats":[{"category":"impact","date":"2018-12-21T19:23:09Z","details":"moderate"}],"title":"CVE-2018-1000816"}]}