Описание
ELSA-2023-2784: grafana security update (MODERATE)
[7.5.15-4]
- resolve CVE-2022-39229 grafana: using email as a username can block other users from signing in
- resolve CVE-2022-27664 golang: net/http: handle server errors after sending GOAWAY
- resolve CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps
- resolve CVE-2022-2880 golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters
- run integration tests in check phase
- update FIPS patch with latest changes in Go packaging
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
grafana
7.5.15-4.el8
Oracle Linux x86_64
grafana
7.5.15-4.el8
Связанные уязвимости
oracle-oval
около 2 лет назад
ELSA-2023-2167: grafana security and enhancement update (MODERATE)
oracle-oval
около 2 лет назад
ELSA-2023-2780: Image Builder security, bug fix, and enhancement update (MODERATE)
oracle-oval
около 2 лет назад
ELSA-2023-2204: Image Builder security, bug fix, and enhancement update (MODERATE)
oracle-oval
больше 1 года назад
ELSA-2024-0121: container-tools:4.0 security update (MODERATE)