RHSA-2024:1501: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.Security Fix(es): grafana: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 9.2.10-8.el9_3 - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 9.2.10-8.el9_3 - Upgrade
Upgrade
redhat/grafana-debugsourceto a version that resolves this vulnerability.Fixed in 9.2.10-8.el9_3 - Upgrade
Upgrade
redhat/grafanato a version that resolves this vulnerability.Fixed in 9.2.10-8.el9_3.aa - Upgrade
Upgrade
redhat/grafana-debuginfoto a version that resolves this vulnerability.Fixed in 9.2.10-8.el9_3.aa - Upgrade
Upgrade
redhat/grafana-debugsourceto a version that resolves this vulnerability.Fixed in 9.2.10-8.el9_3.aa - Compensating control
Apply the Grafana security update addressing CVE-2024-1394 (memory leaks in code encrypting/decrypting RSA payloads) for grafana/golang-fips/openssl.
- Operational
Before applying the Grafana security update, ensure all previously released errata relevant to your system have been applied.
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1501?
The severity of RHSA-2024:1501 is classified as Important.
How do I fix RHSA-2024:1501?
To fix RHSA-2024:1501, you should upgrade to grafana version 9.2.10-8.el9_3.
What vulnerabilities are addressed in RHSA-2024:1501?
RHSA-2024:1501 addresses memory leaks in code encrypting and decrypting RSA payloads, identified by CVE-2024-1394.
Which versions of Grafana are affected by RHSA-2024:1501?
Versions of Grafana up to but not including 9.2.10-8.el9_3 are affected by RHSA-2024:1501.
Is there a specific package I need to upgrade to remediate RHSA-2024:1501?
Yes, you need to upgrade the grafana package to version 9.2.10-8.el9_3 to remediate RHSA-2024:1501.