Описание
ELSA-2026-54243: grafana security update (IMPORTANT)
[9.2.10-32.0.1.el8_10.1]
- Fixes CVE-2024-1442 Add email verification when updating user email [Orabug: 38550520]
[9.2.10-32.1]
- Resolves RHEL-219393: CVE-2026-42127
- Resolves RHEL-211017: CVE-2026-33377
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
grafana
9.2.10-32.0.1.el8_10.1
grafana-selinux
9.2.10-32.0.1.el8_10.1
Oracle Linux x86_64
grafana
9.2.10-32.0.1.el8_10.1
grafana-selinux
9.2.10-32.0.1.el8_10.1
Связанные CVE
Связанные уязвимости
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.