RHSA-2022:5718: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor forGraphite, InfluxDB & OpenTSDB.Security Fix(es): grafana: OAuth account takeover (CVE-2022-31107) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5718?
RHSA-2022:5718 is classified as critical due to the possibility of OAuth account takeover.
How do I fix RHSA-2022:5718?
To fix RHSA-2022:5718, upgrade to Grafana version 7.3.6-5.el8_4 or later.
What is the impact of RHSA-2022:5718?
The impact of RHSA-2022:5718 allows attackers to potentially take over OAuth accounts.
Which versions of Grafana are affected by RHSA-2022:5718?
Versions prior to 7.3.6-5.el8_4 of Grafana are affected by RHSA-2022:5718.
Is there a specific package to update for RHSA-2022:5718?
Yes, the specific package to update for RHSA-2022:5718 is the Grafana package.