RHSA-2022:5720: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for<br>Graphite, InfluxDB & OpenTSDB.<br>Security Fix(es):<br><li> grafana: OAuth account takeover (CVE-2022-31107)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE page(s)<br>listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5720?
The severity of RHSA-2022:5720 is critical due to the potential for OAuth account takeover (CVE-2022-31107).
How do I fix RHSA-2022:5720?
To fix RHSA-2022:5720, you should upgrade to grafana version 6.2.2-9.el8_1 or later.
What is the main vulnerability addressed in RHSA-2022:5720?
The main vulnerability addressed in RHSA-2022:5720 is OAuth account takeover that affects Grafana.
Which software versions are affected by RHSA-2022:5720?
RHSA-2022:5720 affects multiple Grafana packages including grafana, grafana-azure-monitor, and several others all below version 6.2.2-9.el8_1.
What type of software is impacted by RHSA-2022:5720?
RHSA-2022:5720 impacts Grafana, which is an open source metrics dashboard and graph editor.