RHSA-2022:5717: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor forGraphite, InfluxDB & OpenTSDB.Security Fix(es): grafana: OAuth account takeover (CVE-2022-31107) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5717?
The severity of RHSA-2022:5717 is classified as important.
How do I fix RHSA-2022:5717?
To fix RHSA-2022:5717, you should upgrade to Grafana version 7.5.11-3.el8_6.
What vulnerability is addressed in RHSA-2022:5717?
RHSA-2022:5717 addresses an OAuth account takeover vulnerability identified as CVE-2022-31107.
Which versions of Grafana are affected by RHSA-2022:5717?
Versions of Grafana prior to 7.5.11-3.el8_6 are affected by RHSA-2022:5717.
Is there a workaround for RHSA-2022:5717?
There are no specific workarounds provided for RHSA-2022:5717; upgrading is the recommended action.