RHSA-2020:2676: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. <br>Security Fix(es):<br><li> grafana: SSRF incorrect access control vulnerability allows unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2676?
The severity of RHSA-2020:2676 is classified as important due to the SSRF vulnerability allowing unauthorized access.
How do I fix RHSA-2020:2676?
To fix RHSA-2020:2676, update Grafana to version 6.2.2-6.el8_1 or a later version.
What is the nature of the vulnerability in RHSA-2020:2676?
RHSA-2020:2676 addresses an SSRF (Server-Side Request Forgery) vulnerability affecting the Grafana application.
Which Grafana versions are affected by RHSA-2020:2676?
Grafana versions prior to 6.2.2-6.el8_1 are affected by the vulnerability described in RHSA-2020:2676.
Is authentication required to exploit the vulnerability in RHSA-2020:2676?
No, the SSRF vulnerability in RHSA-2020:2676 can be exploited by unauthenticated users.