RHSA-2022:0002: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): golang: net/http: limit growth of header canonicalization cache (CVE-2021-44716) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 7.3.6-4.el8_4 - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.6-4.el8_4 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 7.3.6-4.el8_4.aa - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 7.3.6-4.el8_4.aa - Upgrade
Upgrade
golang: net/httpto a version that resolves this vulnerability.Patch CVE-2021-44716
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0002?
The severity of RHSA-2022:0002 is classified as important.
How do I fix RHSA-2022:0002?
To fix RHSA-2022:0002, upgrade Grafana to version 7.3.6-4.el8_4.
Which versions of Grafana are affected by RHSA-2022:0002?
Grafana versions earlier than 7.3.6-4.el8_4 are affected by RHSA-2022:0002.
What components are affected by RHSA-2022:0002?
RHSA-2022:0002 affects the Grafana and Grafana-debuginfo packages.
Does RHSA-2022:0002 cover multiple architectures?
Yes, RHSA-2022:0002 covers multiple architectures including x86_64 and ppc64le.