Lucene search

K
oraclelinuxOracleLinuxELSA-2023-2784
HistoryMay 24, 2023 - 12:00 a.m.

grafana security update

2023-05-2400:00:00
linux.oracle.com
35
grafana
security update
cve-2022-39229
cve-2022-27664
cve-2022-41715
cve-2022-2880
integration tests
fips patch
unix

EPSS

0.002

Percentile

62.1%

[7.5.15-4]

  • resolve CVE-2022-39229 grafana: using email as a username can block other users from signing in
  • resolve CVE-2022-27664 golang: net/http: handle server errors after sending GOAWAY
  • resolve CVE-2022-41715 golang: regexp/syntax: limit memory used by parsing regexps
  • resolve CVE-2022-2880 golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters
  • run integration tests in check phase
  • update FIPS patch with latest changes in Go packaging