RHSA-2021:3771: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): grafana: Snapshot authentication bypass (CVE-2021-39226) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 7.3.6-3.el8_4 - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.6-3.el8_4 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 7.3.6-3.el8_4.aa - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.6-3.el8_4.aa - Upgrade
Upgrade
grafanato a version that resolves this vulnerability.Fixed in 7.3.6-3.el8_4 - Upgrade
Upgrade
grafana-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.6-3.el8_4
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3771?
The severity of RHSA-2021:3771 is considered important due to the authentication bypass vulnerability.
How do I fix RHSA-2021:3771?
To fix RHSA-2021:3771, update Grafana to version 7.3.6-3.el8_4 or later.
What is the vulnerability associated with RHSA-2021:3771?
RHSA-2021:3771 addresses a snapshot authentication bypass vulnerability identified as CVE-2021-39226.
Which versions of Grafana are affected by RHSA-2021:3771?
Versions of Grafana prior to 7.3.6-3.el8_4 are affected by RHSA-2021:3771.
Is there a specific package that needs to be updated for RHSA-2021:3771?
Yes, the Grafana package specifically needs to be updated to resolve the issue in RHSA-2021:3771.