Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:0401

Опубликовано: 13 фев. 2025
Источник: rocky
Оценка: Important

Описание

Important: grafana security update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • go-git: argument injection via the URL field (CVE-2025-21613)

  • go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies (CVE-2025-21614)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
grafanax86_6421.el8_10grafana-9.2.10-21.el8_10.x86_64.rpm
grafana-selinuxx86_6421.el8_10grafana-selinux-9.2.10-21.el8_10.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
5 месяцев назад

ELSA-2025-0401: grafana security update (IMPORTANT)

CVSS3: 9.8
redos
4 месяца назад

Множественные уязвимости grafana

CVSS3: 9.8
redos
4 месяца назад

Множественные уязвимости trivy

suse-cvrf
4 месяца назад

Security update for trivy

CVSS3: 7.5
ubuntu
5 месяцев назад

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.