RHSA-2020:2641: Important: grafana security update

Published Jun 22, 2020
·
Updated

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Software

56 affected componentsFixes available
redhat/grafana<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-azure-monitor<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-cloudwatch<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-debuginfo<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-elasticsearch<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-graphite<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-influxdb<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-loki<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-mssql<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-mysql<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-opentsdb<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-postgres<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-prometheus<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-stackdriver<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-azure-monitor<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-cloudwatch<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-debuginfo<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-elasticsearch<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-graphite<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-influxdb<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-loki<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-mssql<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-mysql<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-opentsdb<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-postgres<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-prometheus<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-stackdriver<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-azure-monitor<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-cloudwatch<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-debuginfo<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-elasticsearch<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-graphite<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-influxdb<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-loki<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-mssql<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-mysql<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-opentsdb<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-postgres<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-prometheus<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana-stackdriver<6.3.6-2.el8_2
6.3.6-2.el8_2
redhat/grafana<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-azure-monitor<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-cloudwatch<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-debuginfo<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-elasticsearch<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-graphite<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-influxdb<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-loki<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-mssql<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-mysql<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-opentsdb<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-postgres<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-prometheus<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa
redhat/grafana-stackdriver<6.3.6-2.el8_2.aa
6.3.6-2.el8_2.aa

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  2. Upgrade

    Upgrade redhat/grafana-azure-monitor to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  3. Upgrade

    Upgrade redhat/grafana-cloudwatch to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  4. Upgrade

    Upgrade redhat/grafana-debuginfo to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  5. Upgrade

    Upgrade redhat/grafana-elasticsearch to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  6. Upgrade

    Upgrade redhat/grafana-graphite to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  7. Upgrade

    Upgrade redhat/grafana-influxdb to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  8. Upgrade

    Upgrade redhat/grafana-loki to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  9. Upgrade

    Upgrade redhat/grafana-mssql to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  10. Upgrade

    Upgrade redhat/grafana-mysql to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  11. Upgrade

    Upgrade redhat/grafana-opentsdb to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  12. Upgrade

    Upgrade redhat/grafana-postgres to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  13. Upgrade

    Upgrade redhat/grafana-prometheus to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  14. Upgrade

    Upgrade redhat/grafana-stackdriver to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  15. Upgrade

    Upgrade redhat/grafana to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  16. Upgrade

    Upgrade redhat/grafana-azure-monitor to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  17. Upgrade

    Upgrade redhat/grafana-cloudwatch to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  18. Upgrade

    Upgrade redhat/grafana-debuginfo to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  19. Upgrade

    Upgrade redhat/grafana-elasticsearch to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  20. Upgrade

    Upgrade redhat/grafana-graphite to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  21. Upgrade

    Upgrade redhat/grafana-influxdb to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  22. Upgrade

    Upgrade redhat/grafana-loki to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  23. Upgrade

    Upgrade redhat/grafana-mssql to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  24. Upgrade

    Upgrade redhat/grafana-mysql to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  25. Upgrade

    Upgrade redhat/grafana-opentsdb to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  26. Upgrade

    Upgrade redhat/grafana-postgres to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  27. Upgrade

    Upgrade redhat/grafana-prometheus to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  28. Upgrade

    Upgrade redhat/grafana-stackdriver to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2.aa
  29. Upgrade

    Upgrade grafana to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  30. Upgrade

    Upgrade grafana-azure-monitor to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  31. Upgrade

    Upgrade grafana-cloudwatch to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  32. Upgrade

    Upgrade grafana-elasticsearch to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  33. Upgrade

    Upgrade grafana-graphite to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  34. Upgrade

    Upgrade grafana-influxdb to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  35. Upgrade

    Upgrade grafana-loki to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  36. Upgrade

    Upgrade grafana-mssql to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  37. Upgrade

    Upgrade grafana-mysql to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  38. Upgrade

    Upgrade grafana-opentsdb to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  39. Upgrade

    Upgrade grafana-postgres to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  40. Upgrade

    Upgrade grafana-prometheus to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2
  41. Upgrade

    Upgrade grafana-stackdriver to a version that resolves this vulnerability.

    Fixed in 6.3.6-2.el8_2

Event History

Jul 26, 2026
Advisory Published
via Red Hat·04:50 PM
Data Sourced
via Red Hat·04:50 PM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of RHSA-2020:2641?

The severity of RHSA-2020:2641 is classified as moderate due to a SSRF vulnerability in Grafana.

2

How do I fix RHSA-2020:2641?

To fix RHSA-2020:2641, upgrade Grafana to version 6.3.6-2.el8_2 or later.

3

What components are affected by RHSA-2020:2641?

RHSA-2020:2641 affects various Grafana packages including grafana, grafana-azure-monitor, and grafana-cloudwatch.

4

What type of vulnerability is referenced in RHSA-2020:2641?

RHSA-2020:2641 references an SSRF (Server-Side Request Forgery) vulnerability.

5

Is it safe to use versions prior to the fix in RHSA-2020:2641?

Using versions prior to the fix in RHSA-2020:2641 is unsafe as it allows unauthenticated users to exploit the SSRF vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203