Blame SOURCES/010-CVE-2020-13430.patch

d709f2
diff --git a/public/app/plugins/datasource/opentsdb/query_ctrl.ts b/public/app/plugins/datasource/opentsdb/query_ctrl.ts
d709f2
index 8569de2eb0..cbb1790625 100644
d709f2
--- a/public/app/plugins/datasource/opentsdb/query_ctrl.ts
d709f2
+++ b/public/app/plugins/datasource/opentsdb/query_ctrl.ts
d709f2
@@ -2,6 +2,7 @@ import _ from 'lodash';
d709f2
 import kbn from 'app/core/utils/kbn';
d709f2
 import { QueryCtrl } from 'app/plugins/sdk';
d709f2
 import { auto } from 'angular';
d709f2
+import { escapeHtml } from 'app/core/utils/text';
d709f2
 
d709f2
 export class OpenTsQueryCtrl extends QueryCtrl {
d709f2
   static templateUrl = 'partials/query.editor.html';
d709f2
@@ -90,7 +91,7 @@ export class OpenTsQueryCtrl extends QueryCtrl {
d709f2
 
d709f2
   getTextValues(metricFindResult: any) {
d709f2
     return _.map(metricFindResult, value => {
d709f2
-      return value.text;
d709f2
+      return escapeHtml(value.text);
d709f2
     });
d709f2
   }
d709f2