Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21366-1

Опубликовано: 17 июл. 2026
Источник: suse-cvrf

Описание

Security update for grafana

This update for grafana fixes the following issues:

Changes in grafana:

  • CVE-2026-33382: Limit the size of the request body before processing it at several Grafana API endpoints (bsc#1271331)
  • CVE-2026-8595: Fix stored XSS in the table panel (bsc#1271557)

Список пакетов

openSUSE Leap 16.0
grafana-12.4.5-bp160.2.1

Описание

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.


Затронутые продукты
openSUSE Leap 16.0:grafana-12.4.5-bp160.2.1

Ссылки

Описание

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).


Затронутые продукты
openSUSE Leap 16.0:grafana-12.4.5-bp160.2.1

Ссылки