RHSA-2020:2792: Moderate: OpenShift Container Platform 4.4.11 grafana-container security update
Red Hat OpenShift Container Platform is Red Hat's cloud computingKubernetes application platform solution designed for on-premise or privatecloud deployments.Security Fix(es): grafana: SSRF incorrect access control vulnerability allowed unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2792?
The severity of RHSA-2020:2792 is classified as moderate.
What vulnerability is addressed in RHSA-2020:2792?
RHSA-2020:2792 addresses an SSRF incorrect access control vulnerability in Grafana.
How do I fix RHSA-2020:2792?
To fix RHSA-2020:2792, you should update your Grafana installation to the latest version that resolves the vulnerability.
Who is affected by RHSA-2020:2792?
Users of Red Hat OpenShift Container Platform that utilize Grafana are affected by RHSA-2020:2792.
Can unauthenticated users exploit RHSA-2020:2792?
Yes, unauthenticated users can exploit the SSRF vulnerability addressed in RHSA-2020:2792.