Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-2641

Опубликовано: 22 июн. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-2641: grafana security update (IMPORTANT)

[6.3.6-2]

  • fix CVE-2020-13379

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

grafana

6.3.6-2.el8_2

grafana-azure-monitor

6.3.6-2.el8_2

grafana-cloudwatch

6.3.6-2.el8_2

grafana-elasticsearch

6.3.6-2.el8_2

grafana-graphite

6.3.6-2.el8_2

grafana-influxdb

6.3.6-2.el8_2

grafana-loki

6.3.6-2.el8_2

grafana-mssql

6.3.6-2.el8_2

grafana-mysql

6.3.6-2.el8_2

grafana-opentsdb

6.3.6-2.el8_2

grafana-postgres

6.3.6-2.el8_2

grafana-prometheus

6.3.6-2.el8_2

grafana-stackdriver

6.3.6-2.el8_2

Oracle Linux x86_64

grafana

6.3.6-2.el8_2

grafana-azure-monitor

6.3.6-2.el8_2

grafana-cloudwatch

6.3.6-2.el8_2

grafana-elasticsearch

6.3.6-2.el8_2

grafana-graphite

6.3.6-2.el8_2

grafana-influxdb

6.3.6-2.el8_2

grafana-loki

6.3.6-2.el8_2

grafana-mssql

6.3.6-2.el8_2

grafana-mysql

6.3.6-2.el8_2

grafana-opentsdb

6.3.6-2.el8_2

grafana-postgres

6.3.6-2.el8_2

grafana-prometheus

6.3.6-2.el8_2

grafana-stackdriver

6.3.6-2.el8_2

Связанные CVE

Связанные уязвимости

CVSS3: 8.2
ubuntu
около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
redhat
около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
nvd
около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
debian
около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrec ...

CVSS3: 5.8
github
больше 3 лет назад

Server Side Request Forgery in Grafana