First published: Tue Jul 26 2022(Updated: )
Grafana is an open source, feature rich metrics dashboard and graph editor for<br>Graphite, InfluxDB & OpenTSDB.<br>Security Fix(es):<br><li> grafana: OAuth account takeover (CVE-2022-31107)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grafana | <7.5.11-5.el9_0 | 7.5.11-5.el9_0 |
redhat/grafana | <7.5.11-5.el9_0 | 7.5.11-5.el9_0 |
redhat/grafana-debuginfo | <7.5.11-5.el9_0 | 7.5.11-5.el9_0 |
redhat/grafana-debuginfo | <7.5.11-5.el9_0 | 7.5.11-5.el9_0 |
redhat/grafana | <7.5.11-5.el9_0 | 7.5.11-5.el9_0 |
redhat/grafana-debuginfo | <7.5.11-5.el9_0 | 7.5.11-5.el9_0 |
redhat/grafana | <7.5.11-5.el9_0.aa | 7.5.11-5.el9_0.aa |
redhat/grafana-debuginfo | <7.5.11-5.el9_0.aa | 7.5.11-5.el9_0.aa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:5716 is classified as important.
You can fix RHSA-2022:5716 by updating Grafana to version 7.5.11-5.el9_0.
RHSA-2022:5716 addresses an OAuth account takeover vulnerability identified as CVE-2022-31107.
Versions of Grafana prior to 7.5.11-5.el9_0 are affected by RHSA-2022:5716.
There are no specific workarounds recommended for the vulnerabilities addressed in RHSA-2022:5716 other than applying the update.