stable
FEDORA-2022-83405f9d5b created by agerstmayr 8 months ago for Fedora 34
  • update to 7.5.15 tagged upstream community sources, see CHANGELOG
  • resolve CVE-2022-21673 grafana: Forward OAuth Identity Token can allow users to access some data sources
  • resolve CVE-2022-21702 grafana: XSS vulnerability in data source handling
  • resolve CVE-2022-21703 grafana: CSRF vulnerability can lead to privilege escalation
  • resolve CVE-2022-21713 grafana: IDOR vulnerability can lead to information disclosure
  • resolve CVE-2021-23648 sanitize-url: XSS
  • resolve CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter
  • declare Node.js dependencies of subpackages
  • make vendor and webpack tarballs reproducible

How to install

sudo dnf upgrade --refresh --advisory=FEDORA-2022-83405f9d5b

This update has been submitted for testing by agerstmayr.

8 months ago

This update's test gating status has been changed to 'ignored'.

8 months ago

agerstmayr edited this update.

8 months ago

This update has been pushed to testing.

8 months ago

This update's test gating status has been changed to 'passed'.

8 months ago

agerstmayr edited this update.

New build(s):

  • grafana-7.5.15-2.fc34

Removed build(s):

  • grafana-7.5.15-1.fc34

Karma has been reset.

8 months ago

This update has been submitted for testing by agerstmayr.

8 months ago

This update's test gating status has been changed to 'ignored'.

8 months ago

This update has been pushed to testing.

8 months ago

This update's test gating status has been changed to 'passed'.

8 months ago

This update has been submitted for stable by bodhi.

8 months ago

This update has been pushed to stable.

8 months ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
8 months ago
in testing
8 months ago
in stable
8 months ago
modified
8 months ago
BZ#2046615 CVE-2022-21673 grafana: Forward OAuth Identity Token can allow users to access some data sources [fedora-all]
0
0
BZ#2053453 CVE-2022-21702 grafana: XSS vulnerability in data source handling [fedora-all]
0
0
BZ#2053454 CVE-2022-21703 grafana: CSRF vulnerability can lead to privilege escalation [fedora-all]
0
0
BZ#2053455 CVE-2022-21713 grafana: IDOR vulnerability can lead to information disclosure [fedora-all]
0
0
BZ#2066482 CVE-2021-23648 grafana: sanitize-url: XSS [fedora-all]
0
0
BZ#2067414 CVE-2022-21698 grafana: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-all]
0
0
BZ#2067452 CVE-2022-21698 grafana: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-34]
0
0

Automated Test Results