Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54243

Опубликовано: 13 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-54243: grafana security update (IMPORTANT)

[9.2.10-32.0.1.el8_10.1]

  • Fixes CVE-2024-1442 Add email verification when updating user email [Orabug: 38550520]

[9.2.10-32.1]

  • Resolves RHEL-219393: CVE-2026-42127
  • Resolves RHEL-211017: CVE-2026-33377

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

grafana

9.2.10-32.0.1.el8_10.1

grafana-selinux

9.2.10-32.0.1.el8_10.1

Oracle Linux x86_64

grafana

9.2.10-32.0.1.el8_10.1

grafana-selinux

9.2.10-32.0.1.el8_10.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
nvd
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.1
ubuntu
4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
redhat
4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
nvd
4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.