RHSA-2024:2568: Moderate: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.Security Fix(es): grafana: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394) grafana: vulnerable to authorization bypass (CVE-2024-1313) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2568?
The severity of RHSA-2024:2568 is categorized as moderate due to memory leaks related to RSA payload encryption and decryption.
How do I fix RHSA-2024:2568?
To fix RHSA-2024:2568, update the grafana package to version 9.2.10-16.el9_4 or later.
What are the affected products in RHSA-2024:2568?
RHSA-2024:2568 affects several Red Hat Enterprise Linux products including x86_64, POWER, and ARM architectures.
What vulnerabilities are addressed in RHSA-2024:2568?
RHSA-2024:2568 addresses memory leak vulnerabilities in the grafana package related to RSA payload handling (CVE-2024-1394).
Is there a specific version recommended to resolve RHSA-2024:2568?
Yes, the recommended version to resolve RHSA-2024:2568 is grafana 9.2.10-16.el9_4.