First published: Tue Nov 03 2020(Updated: )
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. <br>The following packages have been upgraded to a later upstream version: grafana (6.7.4). (BZ#1807323)<br>Security Fix(es):<br><li> grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen (CVE-2018-18624)</li> <li> grafana: arbitrary file read via MySQL data source (CVE-2019-19499)</li> <li> grafana: stored XSS (CVE-2020-11110)</li> <li> grafana: XSS annotation popup vulnerability (CVE-2020-12052)</li> <li> grafana: XSS via column.title or cellLinkTooltip (CVE-2020-12245)</li> <li> grafana: information disclosure through world-readable /var/lib/grafana/grafana.db (CVE-2020-12458)</li> <li> grafana: information disclosure through world-readable grafana configuration files (CVE-2020-12459)</li> <li> grafana: XSS via the OpenTSDB datasource (CVE-2020-13430)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-azure-monitor | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-cloudwatch | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-debuginfo | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-elasticsearch | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-graphite | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-influxdb | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-loki | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-mssql | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-mysql | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-opentsdb | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-postgres | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-prometheus | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-stackdriver | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-azure-monitor | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-cloudwatch | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-debuginfo | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-elasticsearch | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-graphite | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-influxdb | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-loki | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-mssql | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-mysql | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-opentsdb | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-postgres | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-prometheus | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-stackdriver | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-azure-monitor | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-cloudwatch | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-debuginfo | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-elasticsearch | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-graphite | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-influxdb | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-loki | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-mssql | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-mysql | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-opentsdb | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-postgres | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-prometheus | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana-stackdriver | <6.7.4-3.el8 | 6.7.4-3.el8 |
redhat/grafana | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-azure-monitor | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-cloudwatch | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-debuginfo | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-elasticsearch | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-graphite | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-influxdb | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-loki | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-mssql | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-mysql | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-opentsdb | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-postgres | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-prometheus | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
redhat/grafana-stackdriver | <6.7.4-3.el8.aa | 6.7.4-3.el8.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.