First published: Mon Jul 06 2020(Updated: )
Red Hat OpenShift Container Platform is Red Hat's cloud computing<br>Kubernetes application platform solution designed for on-premise or private<br>cloud deployments.<br>Security Fix(es):<br><li> grafana: SSRF incorrect access control vulnerability allowed unauthenticated users to make grafana send HTTP requests to any URL (CVE-2020-13379)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:2792 is classified as moderate.
RHSA-2020:2792 addresses an SSRF incorrect access control vulnerability in Grafana.
To fix RHSA-2020:2792, you should update your Grafana installation to the latest version that resolves the vulnerability.
Users of Red Hat OpenShift Container Platform that utilize Grafana are affected by RHSA-2020:2792.
Yes, unauthenticated users can exploit the SSRF vulnerability addressed in RHSA-2020:2792.