shield
Security update for grafana
SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-362
This update for grafana fixes the following issues: - Version update from 8.5.13 to 8.5.15 (jsc#PED-2617): * CVE-2022-39306: Security fix for privilege escalation (bsc#1205225) * CVE-2022-39307: Omit error from http response when user does not exists (bsc#1205227) * CVE-2022-39201: Do not forward login cookie in outgoing requests (bsc#1204303) * CVE-2022-31130: Make proxy endpoints not leak sensitive HTTP headers (bsc#1204305) * CVE-2022-31123: Fix plugin signature bypass (bsc#1204302) * CVE-2022-39229: Fix blocking other users from signing in (bsc#1204304)
-
Release DateFeb 10 2023
-
ReferencesBugzilla: 1204304, 1204303, 1205225, 1204305, 1205227, 1204302
CVEs: CVE-2022-39307, CVE-2022-31130, CVE-2022-39229, CVE-2022-39306, CVE-2022-39201, CVE-2022-31123 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Package Hub 15.4 x86_64
-
Packagesgrafana
The open-source platform for monitoring and observability8.5.15-150200.3.32.1 lock rpm lock src
SUSE Package Hub 15.4 aarch64
-
Packagesgrafana
The open-source platform for monitoring and observability8.5.15-150200.3.32.1 lock rpm lock src
SUSE Package Hub 15.4 ppc64le
-
Packagesgrafana
The open-source platform for monitoring and observability8.5.15-150200.3.32.1 lock rpm lock src
SUSE Package Hub 15.4 s390x
-
Packagesgrafana
The open-source platform for monitoring and observability8.5.15-150200.3.32.1 lock rpm lock src