Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 32: FEDORA-2020-c6b0c7ebbb Critical: Grafana Info Disclosure

fedora
Calendar Grey May 13, 2020
Dist Fedora Esm H88
Upgrade to Grafana version 6.7.3, addressing essential patches for security flaws related to information leakage. Additional update specifics provided.
rebase to upstream Grafana 6.7.3 - including fix for CVE-2020-12458 and CVE-2020-12459

Summary

Grafana is an open source, feature rich metrics dashboard and graph editor for

Graphite, InfluxDB & OpenTSDB.

rebase to upstream Grafana 6.7.3 - including fix for CVE-2020-12458 and

CVE-2020-12459

* Tue Apr 28 2020 Andreas Gerstmayr 6.7.3-1

- update to 6.7.3 tagged upstream community sources, see CHANGELOG

- add scripts to list Go dependencies and bundled npmjs dependencies

- set Grafana version in Grafana UI and grafana-cli --version

- declare README.md as documentation of datasource plugins

- create grafana.db on first installation (fixes RH BZ #1805472)

- change permissions of /var/lib/grafana to 750 (CVE-2020-12458)

- change permissions of /var/lib/grafana/grafana.db to 640 and

user/group grafana:grafana (CVE-2020-12458)

- change permissions of grafana.ini and ldap.toml to 640 (CVE-2020-12459)

[ 1 ] Bug #1827765 - CVE-2020-12458 grafana: information disclosure through world-readable /var/lib/grafana/grafana.db

https://bugzilla.redhat.com/show_bug.cgi?id=1827765

[ 2 ] Bug #1829724 - CVE-2020-12459 grafana: information disclosure through world-readable grafana configuration files

https://bugzilla.redhat.com/show_bug.cgi?id=1829724

su -c 'dnf upgrade --advisory FEDORA-2020-c6b0c7ebbb' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 6.7.3
Release: 1.fc32
Summary: Metrics dashboard and graph editor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here