RHSA-2025:8684: Important: grafana security update
Published Jun 9, 2025
·Updated
Important: grafana security update
Affected Software
16 affected componentsFixes available
Red Hat Red Hat Enterprise Linux Server - AUS
redhat/grafana<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-azure-monitor<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-cloudwatch<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-debuginfo<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-elasticsearch<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-graphite<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-influxdb<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-loki<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-mssql<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-mysql<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-opentsdb<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-postgres<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-prometheus<6.3.6-7.el8_2
6.3.6-7.el8_2
redhat/grafana-stackdriver<6.3.6-7.el8_2
6.3.6-7.el8_2
Remediation
Event History
Jun 9, 2025
Advisory Published
via Red Hat·12:20 PM
Jun 29, 2025
Advisory Published
via Red Hat·01:10 PM
Data Sourced
via Red Hat·01:10 PM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
What is the severity of RHSA-2025:8684?
The severity of RHSA-2025:8684 is classified as important.
2
What vulnerabilities are addressed in RHSA-2025:8684?
RHSA-2025:8684 addresses a Cross-site Scripting (XSS) vulnerability in Grafana via Custom Frontend Plugins and an Open Redirect vulnerability (CVE-2025-4123).
3
How do I fix RHSA-2025:8684?
To fix RHSA-2025:8684, upgrade to the specified package version 6.3.6-7.el8_2 for Grafana and its related packages.
4
Which software packages are affected by RHSA-2025:8684?
Affected packages include various Grafana packages such as grafana, grafana-cloudwatch, and grafana-influxdb among others.
5
Is there a workaround for RHSA-2025:8684?
There are no listed workarounds for RHSA-2025:8684; the recommended action is to apply the security update.