This update for grafana fixes the following issues:
grafana was updated from version 11.5.5 to 11.5.10:
* Security issues fixed:
* CVE-2025-64751: Dropped experimental implementation of authorization Zanzana
server/client (version 11.5.10) (bsc#1254113)
* CVE-2025-47911: Fixed parsing HTML documents (version 11.5.10) (bsc#1251454)
* CVE-2025-58190: Fixed excessive memory consumption (version 11.5.10)
(bsc#1251657)
* CVE-2025-11065: Fixed sensitive information leak in logs (version 11.5.9)
(bsc#1250616)
* CVE-2025-6023: Fixed cross-site-scripting via scripted dashboards (version
11.5.7) (bsc#1246735)
* CVE-2025-6197: Fixed open redirect in organization switching (version
11.5.7) (bsc#1246736)
* CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer
level users (version 11.5.6) (bsc#1245302)
* Other changes, new features and bugs fixed:
* Version 11.5.10:
* Use forked wire from Grafana repository instead of...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-4482=1
* SUSE Package Hub 15 15-SP6
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-4482=1
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-4482=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* grafana-debuginfo-11.5.10-150200.3.80.1
* grafana-11.5.10-150200.3.80.1
* SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64)
* grafana-debuginfo-11.5.10-150200.3.80.1
* grafana-11.5.10-150200.3.80.1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* grafana-debuginfo-11.5.10-150200.3.80.1
* grafana-11.5.10-150200.3.80.1
* bsc#1245302
* bsc#1246735
* bsc#1246736
* bsc#1250616
* bsc#1251454
* bsc#1251657
* bsc#1254113
* jsc#MSQA-1034
* jsc#PED-14178
## References:
* https://www.suse.com/security/cve/CVE-2025-11065.html
* https://www.suse.com/security/cve/CVE-2025-3415.html
* https://www.suse.com/security/cve/CVE-2025-47911.html
* https://www.suse.com/security/cve/CVE-2025-58190.html
* https://www.suse.com/security/cve/CVE-2025-6023.html
* https://www.suse.com/security/cve/CVE-2025-6197.html
* https://www.suse.com/security/cve/CVE-2025-64751.html
* https://bugzilla.suse.com/show_bug.cgi?id=1245302
* https://bugzilla.suse.com/show_bug.cgi?id=1246735
* https://bugzilla.suse.com/show_bug.cgi?id=1246736
* https://bugzilla.suse.com/show_bug.cgi?id=1250616
* https://bugzilla.suse.com/show_bug.cgi?id=1251454
* https://bugzilla.suse.com/show_bug.cgi?id=1251657
* https://bugzilla.suse.com/show_bug.cgi?id=1254113
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=https%3A%2F%2Fjira.suse.com%2Fbrowse%2FMSQA-1034
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.