RHSA-2020:4682: Moderate: grafana security, bug fix, and enhancement update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. The following packages have been upgraded to a later upstream version: grafana (6.7.4). (BZ#1807323)Security Fix(es): grafana: XSS vulnerability via a column style on the "Dashboard > Table Panel" screen (CVE-2018-18624) grafana: arbitrary file read via MySQL data source (CVE-2019-19499) grafana: stored XSS (CVE-2020-11110) grafana: XSS annotation popup vulnerability (CVE-2020-12052) grafana: XSS via column.title or cellLinkTooltip (CVE-2020-12245) grafana: information disclosure through world-readable /var/lib/grafana/grafana.db (CVE-2020-12458) grafana: information disclosure through world-readable grafana configuration files (CVE-2020-12459) grafana: XSS via the OpenTSDB datasource (CVE-2020-13430) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-azure-monitorto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-cloudwatchto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-elasticsearchto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-graphiteto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-influxdbto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-lokito a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-mssqlto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-mysqlto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-opentsdbto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-postgresto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-prometheusto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafana-stackdriverto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-azure-monitorto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-cloudwatchto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-elasticsearchto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-graphiteto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-influxdbto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-lokito a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-mssqlto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-mysqlto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-opentsdbto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-postgresto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-prometheusto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa - Upgrade
Upgrade
redhat/grafana-stackdriverto a version that resolves this vulnerability.Fixed in 6.7.4-3.el8.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4682?
The severity of RHSA-2020:4682 is classified as important due to an XSS vulnerability in Grafana.
How do I fix RHSA-2020:4682?
To fix RHSA-2020:4682, upgrade Grafana to version 6.7.4-3.el8 or later.
What does RHSA-2020:4682 affect?
RHSA-2020:4682 affects various Grafana packages including grafana, grafana-azure-monitor, grafana-cloudwatch, and others on Red Hat Enterprise Linux.
What type of vulnerability is addressed by RHSA-2020:4682?
RHSA-2020:4682 addresses an XSS (Cross-Site Scripting) vulnerability affecting Grafana.
Is there a workaround for RHSA-2020:4682?
There is no disclosed workaround for RHSA-2020:4682, and upgrading is recommended as the primary solution.