Lucene search

K
oraclelinuxOracleLinuxELSA-2023-2167
HistoryMay 15, 2023 - 12:00 a.m.

grafana security and enhancement update

2023-05-1500:00:00
linux.oracle.com
23
grafana
security update
enhancement
cve-2022-39229
cve-2022-2880
cve-2022-41715
cve-2022-35957
unix

EPSS

0.003

Percentile

68.6%

[9.0.9-2]

  • resolve CVE-2022-39229 grafana: Using email as a username can prevent other users from signing in
  • resolve CVE-2022-2880 CVE-2022-41715 grafana: various flaws
    [9.0.9-1]
  • update to 9.0.9 tagged upstream community sources, see CHANGELOG
  • resolve CVE-2022-35957 grafana: Escalation from admin to server admin when auth proxy is used (rhbz#2125530)
    [9.0.8-2]
  • bump NVR
    [9.0.8-1]
  • update to 9.0.8 tagged upstream community sources, see CHANGELOG
  • do not list /usr/share/grafana/conf twice
  • drop makefile in favor of create_bundles.sh script
  • sync provides/obsoletes with CentOS versions
  • drop husky patch