RHSA-2025:7892: Important: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): grafana: Cross-site Scripting (XSS) in Grafana via Custom Frontend Plugins and Open Redirect (CVE-2025-4123) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:7892?
The severity of RHSA-2025:7892 is categorized as Important.
How do I fix RHSA-2025:7892?
To fix RHSA-2025:7892, update the Grafana package to version 10.2.6-17.el10_0 or later.
What vulnerabilities are addressed in RHSA-2025:7892?
RHSA-2025:7892 addresses a Cross-site Scripting (XSS) vulnerability in Grafana via Custom Frontend Plugins and an Open Redirect.
Which software versions are affected by RHSA-2025:7892?
RHSA-2025:7892 affects various versions of Red Hat Enterprise Linux and Grafana packages.
Is there a specific Grafana package version to install for RHSA-2025:7892?
Yes, the recommended Grafana package version to install for RHSA-2025:7892 is 10.2.6-17.el10_0.