[FEDORA-2022-c5383675d9] Fedora 36: grafana

Severity High
Affected Packages 1
CVEs 6
  • update to 7.5.15 tagged upstream community sources, see CHANGELOG - resolve CVE-2022-21673 grafana: Forward OAuth Identity Token can allow users to access some data sources - resolve CVE-2022-21702 grafana: XSS vulnerability in data source handling - resolve CVE-2022-21703 grafana: CSRF vulnerability can lead to privilege escalation - resolve CVE-2022-21713 grafana: IDOR vulnerability can lead to information disclosure - resolve CVE-2021-23648 sanitize-url: XSS - resolve CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter - declare Node.js dependencies of subpackages - make vendor and webpack tarballs reproducible
Package Affected Version
pkg:rpm/fedora/grafana?distro=fedora-36 < 7.5.15.2.fc36
ID
FEDORA-2022-c5383675d9
Severity
high
Severity from
CVE-2022-21703
URL
https://bodhi.fedoraproject.org/updates/FEDORA-2022-c5383675d9
Published
2022-05-07T04:56:19
(2 years ago)
Modified
2022-05-07T04:56:19
(2 years ago)
Rights
Copyright 2022 Red Hat, Inc.
Other Advisories
Source # ID Name URL
Bugzilla 2053454 Bug #2053454 - CVE-2022-21703 grafana: CSRF vulnerability can lead to privilege escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2053454
Bugzilla 2066482 Bug #2066482 - CVE-2021-23648 grafana: sanitize-url: XSS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2066482
Bugzilla 2067414 Bug #2067414 - CVE-2022-21698 grafana: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2067414
Bugzilla 2053455 Bug #2053455 - CVE-2022-21713 grafana: IDOR vulnerability can lead to information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2053455
Bugzilla 2046615 Bug #2046615 - CVE-2022-21673 grafana: Forward OAuth Identity Token can allow users to access some data sources [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2046615
Bugzilla 2053453 Bug #2053453 - CVE-2022-21702 grafana: XSS vulnerability in data source handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2053453
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/grafana?distro=fedora-36 fedora grafana < 7.5.15.2.fc36 fedora-36
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...