[openSUSE-SU-2022:0140-1] Security update for grafana
Severity
Important
Affected Packages
4
CVEs
2
Security update for grafana
This update for grafana fixes the following issues:
- CVE-2021-39226: Fixed snapshot authentication bypass (bsc#1191454)
- CVE-2021-43813: Fixed markdown path traversal (bsc#1193688)
Package | Affected Version |
---|---|
pkg:rpm/opensuse/grafana?arch=x86_64&distro=opensuse-leap-15.3 | < 7.5.12-3.18.1 |
pkg:rpm/opensuse/grafana?arch=s390x&distro=opensuse-leap-15.3 | < 7.5.12-3.18.1 |
pkg:rpm/opensuse/grafana?arch=ppc64le&distro=opensuse-leap-15.3 | < 7.5.12-3.18.1 |
pkg:rpm/opensuse/grafana?arch=aarch64&distro=opensuse-leap-15.3 | < 7.5.12-3.18.1 |
- ID
- openSUSE-SU-2022:0140-1
- Severity
- important
- URL
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZUS4G6GRHNJN7AR53SGJABSHRZM3XMOY/
- Published
-
2022-01-20T12:25:15
(2 years ago) - Modified
-
2022-01-20T12:25:15
(2 years ago) - Rights
- Copyright 2024 SUSE LLC. All rights reserved.
- Other Advisories
-
- ALPINE:CVE-2021-43813
- ALSA-2021:3771
- ALSA-2022:1781
- ASA-202112-11
- CISA-2022:0825
- ELSA-2021-3771
- ELSA-2022-1781
- FEDORA-2021-01588ab0bf
- FEDORA-2021-dd83dc8b0b
- FEDORA-2022-6e6b59a682
- FEDORA-2022-c6ae206be7
- FREEBSD:757EE63B-269A-11EC-A616-6C3BE5272ACD
- FREEBSD:A994FF7D-5B3F-11EC-8398-6C3BE5272ACD
- RHSA-2021:3771
- RHSA-2022:1781
- RLSA-2021:3771
- RLSA-2022:1781
- SUSE-SU-2022:0138-1
- SUSE-SU-2022:0139-1
- SUSE-SU-2022:0310-1
- SUSE-SU-2022:0311-1
- SUSE-SU-2022:0751-1
- SUSE-SU-2022:1396-1
- SUSE-SU-2022:1729-1
- SUSE-SU-2022:2134-1
- SUSE-SU-2022:3338-1
- SUSE-SU-2022:3339-1
- SUSE-SU-2022:3425-1
- SUSE-SU-2022:4428-1
- SUSE-SU-2022:4437-1
- SUSE-SU-2022:4439-1
- SUSE-SU-2024:0191-1
- SUSE-SU-2024:0196-1
Source | # ID | Name | URL |
---|---|---|---|
Suse | SUSE ratings | https://www.suse.com/support/security/rating/ | |
Suse | URL of this CSAF notice | https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2022_0140-1.json | |
Suse | URL for openSUSE-SU-2022:0140-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZUS4G6GRHNJN7AR53SGJABSHRZM3XMOY/ | |
Suse | E-Mail link for openSUSE-SU-2022:0140-1 | https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZUS4G6GRHNJN7AR53SGJABSHRZM3XMOY/ | |
Bugzilla | SUSE Bug 1191454 | https://bugzilla.suse.com/1191454 | |
Bugzilla | SUSE Bug 1193688 | https://bugzilla.suse.com/1193688 | |
CVE | SUSE CVE CVE-2021-39226 page | https://www.suse.com/security/cve/CVE-2021-39226/ | |
CVE | SUSE CVE CVE-2021-43813 page | https://www.suse.com/security/cve/CVE-2021-43813/ |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/opensuse/grafana?arch=x86_64&distro=opensuse-leap-15.3 | opensuse | grafana | < 7.5.12-3.18.1 | opensuse-leap-15.3 | x86_64 | |
Affected | pkg:rpm/opensuse/grafana?arch=s390x&distro=opensuse-leap-15.3 | opensuse | grafana | < 7.5.12-3.18.1 | opensuse-leap-15.3 | s390x | |
Affected | pkg:rpm/opensuse/grafana?arch=ppc64le&distro=opensuse-leap-15.3 | opensuse | grafana | < 7.5.12-3.18.1 | opensuse-leap-15.3 | ppc64le | |
Affected | pkg:rpm/opensuse/grafana?arch=aarch64&distro=opensuse-leap-15.3 | opensuse | grafana | < 7.5.12-3.18.1 | opensuse-leap-15.3 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |