Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2022-3765


Security update for grafana


Type: security
Severity: important
Issued: 2022-10-26
Description:
This update for grafana fixes the following issues:

  Updated to version 8.3.10 (jsc#SLE-24565, jsc#SLE-23422, jsc#SLE-23439):

  - CVE-2022-31097: Fixed XSS vulnerability in the Unified Alerting (bsc#1201535).
  - CVE-2022-31107: Fixed OAuth account takeover vulnerability (bsc#1201539).
  - CVE-2022-21702: Fixed XSS through attacker-controlled data source (bsc#1195726).
  - CVE-2022-21703: Fixed Cross Site Request Forgery (bsc#1195727).
  - CVE-2022-21713: Fixed Teams API IDOR (bsc#1195728).

  

              

Packages


  • grafana-8.3.10-150200.3.26.1