[RLSA-2024:1646] grafana security and bug fix update

Severity Important
Affected Packages 2
CVEs 1

An update is available for grafana. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)

Bug Fix(es):

  • TRIAGE CVE-2024-1394 grafana: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (JIRA:Rocky Linux-30543)
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/rockylinux/grafana?arch=x86_64&distro=rockylinux-8.9 rockylinux grafana < 9.2.10-8.el8_9 rockylinux-8.9 x86_64
Affected pkg:rpm/rockylinux/grafana?arch=aarch64&distro=rockylinux-8.9 rockylinux grafana < 9.2.10-8.el8_9 rockylinux-8.9 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...