Описание
Recommended update for grafana
This update for grafana fixes the following issues:
- Fixed changelog entries for the Bugzilla trackers related to previously implemented security fixes (no source code changes)
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP5
grafana-9.5.8-150200.3.53.2
openSUSE Leap 15.5
grafana-9.5.8-150200.3.53.2
Ссылки
- Link for SUSE-RU-2024:0511-1
- E-Mail link for SUSE-RU-2024:0511-1
- SUSE Security Ratings
- SUSE Bug 1192154
- SUSE Bug 1192696
- SUSE Bug 1200480
- SUSE Bug 1218843
- SUSE Bug 1218844
- SUSE CVE CVE-2020-7753 page
- SUSE CVE CVE-2021-3807 page
- SUSE CVE CVE-2021-3918 page
- SUSE CVE CVE-2021-43138 page
- SUSE CVE CVE-2022-0155 page
Описание
All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:grafana-9.5.8-150200.3.53.2
openSUSE Leap 15.5:grafana-9.5.8-150200.3.53.2
Ссылки
- CVE-2020-7753
- SUSE Bug 1218843
Описание
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:grafana-9.5.8-150200.3.53.2
openSUSE Leap 15.5:grafana-9.5.8-150200.3.53.2
Ссылки
- CVE-2021-3807
- SUSE Bug 1192154
Описание
json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:grafana-9.5.8-150200.3.53.2
openSUSE Leap 15.5:grafana-9.5.8-150200.3.53.2
Ссылки
- CVE-2021-3918
- SUSE Bug 1192696
Описание
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:grafana-9.5.8-150200.3.53.2
openSUSE Leap 15.5:grafana-9.5.8-150200.3.53.2
Ссылки
- CVE-2021-43138
- SUSE Bug 1200480
Описание
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:grafana-9.5.8-150200.3.53.2
openSUSE Leap 15.5:grafana-9.5.8-150200.3.53.2
Ссылки
- CVE-2022-0155
- SUSE Bug 1218844