mirror of
https://github.com/grafana/grafana.git
synced 2025-02-25 18:55:37 -06:00
Security: Fix annotation popup XSS vulnerability (#23813)
Co-authored-by: Marcus Efraimsson <marcus.efraimsson@gmail.com>
This commit is contained in:
parent
645dc944db
commit
3955e8cbad
@ -72,7 +72,7 @@ export function annotationTooltipDirective(
|
|||||||
tooltip += '<div class="graph-annotation__body">';
|
tooltip += '<div class="graph-annotation__body">';
|
||||||
|
|
||||||
if (text) {
|
if (text) {
|
||||||
tooltip += '<div>' + sanitizeString(text.replace(/\n/g, '<br>')) + '</div>';
|
tooltip += '<div ng-non-bindable>' + sanitizeString(text.replace(/\n/g, '<br>')) + '</div>';
|
||||||
}
|
}
|
||||||
|
|
||||||
const tags = event.tags;
|
const tags = event.tags;
|
||||||
|
Loading…
Reference in New Issue
Block a user