RHSA-2022:5716: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor forGraphite, InfluxDB & OpenTSDB.Security Fix(es): grafana: OAuth account takeover (CVE-2022-31107) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5716?
The severity of RHSA-2022:5716 is classified as important.
How do I fix RHSA-2022:5716?
You can fix RHSA-2022:5716 by updating Grafana to version 7.5.11-5.el9_0.
What vulnerability is addressed in RHSA-2022:5716?
RHSA-2022:5716 addresses an OAuth account takeover vulnerability identified as CVE-2022-31107.
Which versions of Grafana are affected by RHSA-2022:5716?
Versions of Grafana prior to 7.5.11-5.el9_0 are affected by RHSA-2022:5716.
Is there a workaround for the vulnerabilities fixed in RHSA-2022:5716?
There are no specific workarounds recommended for the vulnerabilities addressed in RHSA-2022:5716 other than applying the update.