stable
FEDORA-2022-9dd03cab55 created by agerstmayr 6 months ago for Fedora 35
  • update to 7.5.15 tagged upstream community sources, see CHANGELOG
  • resolve CVE-2022-21673 grafana: Forward OAuth Identity Token can allow users to access some data sources
  • resolve CVE-2022-21702 grafana: XSS vulnerability in data source handling
  • resolve CVE-2022-21703 grafana: CSRF vulnerability can lead to privilege escalation
  • resolve CVE-2022-21713 grafana: IDOR vulnerability can lead to information disclosure
  • resolve CVE-2021-23648 sanitize-url: XSS
  • resolve CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter
  • declare Node.js dependencies of subpackages
  • make vendor and webpack tarballs reproducible

How to install

sudo dnf upgrade --refresh --advisory=FEDORA-2022-9dd03cab55

This update has been submitted for testing by agerstmayr.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

agerstmayr edited this update.

6 months ago

This update has been pushed to testing.

6 months ago

This update's test gating status has been changed to 'passed'.

6 months ago

agerstmayr edited this update.

New build(s):

  • grafana-7.5.15-2.fc35

Removed build(s):

  • grafana-7.5.15-1.fc35

Karma has been reset.

6 months ago

This update has been submitted for testing by agerstmayr.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

This update has been pushed to testing.

6 months ago

This update's test gating status has been changed to 'passed'.

6 months ago

This update has been submitted for stable by bodhi.

6 months ago

This update has been pushed to stable.

6 months ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
6 months ago
in testing
6 months ago
in stable
6 months ago
modified
6 months ago
BZ#2046615 CVE-2022-21673 grafana: Forward OAuth Identity Token can allow users to access some data sources [fedora-all]
0
0
BZ#2053453 CVE-2022-21702 grafana: XSS vulnerability in data source handling [fedora-all]
0
0
BZ#2053454 CVE-2022-21703 grafana: CSRF vulnerability can lead to privilege escalation [fedora-all]
0
0
BZ#2053455 CVE-2022-21713 grafana: IDOR vulnerability can lead to information disclosure [fedora-all]
0
0
BZ#2066482 CVE-2021-23648 grafana: sanitize-url: XSS [fedora-all]
0
0
BZ#2067414 CVE-2022-21698 grafana: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-all]
0
0
BZ#2067446 CVE-2022-21698 grafana: prometheus/client_golang: Denial of service using InstrumentHandlerCounter [fedora-35]
0
0

Automated Test Results