This update for grafana fixes the following issues:
grafana was updated from version 10.4.15 to 11.5.5 (jsc#PED-12918):
* Security issues fixed:
* CVE-2025-4123: Fix cross-site scripting vulnerability (bsc#1243714).
* CVE-2025-22872: Bump golang.org/x/net/html (bsc#1241809)
* CVE-2025-3580: Prevent unauthorized server admin deletion (bsc#1243672).
* CVE-2025-29923: Bump github.com/redis/go-redis/v9 to 9.6.3.
* CVE-2025-3454: Sanitize paths before evaluating access to route (bsc#1241683).
* CVE-2025-2703: Fix built-in XY Chart plugin (bsc#1241687).
* CVE-2025-22870: Bump golang.org/x/net (bsc#1238703).
* CVE-2024-9476: Fix Migration Assistant issue (bsc#1233343)
* CVE-2024-9264: SQL Expressions (bsc#1231844)
* CVE-2023-45288: Bump golang.org/x/net (bsc#1236510)
* CVE-2025-22870: Bump golang.org/x/net to version 0.37.0 (bsc#1238686)
* Potential breaking changes in version 11.5.0:
* Loki: Default to /labels API with query param...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-1991=1
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-1991=1
* SUSE Package Hub 15 15-SP6
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1991=1
* SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
* grafana-debuginfo-11.5.5-150200.3.72.2
* grafana-11.5.5-150200.3.72.2
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* grafana-debuginfo-11.5.5-150200.3.72.2
* grafana-11.5.5-150200.3.72.2
* SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64)
* grafana-debuginfo-11.5.5-150200.3.72.2
* grafana-11.5.5-150200.3.72.2
* bsc#1231844
* bsc#1233343
* bsc#1236510
* bsc#1236516
* bsc#1238686
* bsc#1238703
* bsc#1241683
* bsc#1241687
* bsc#1241809
* bsc#1243672
* bsc#1243714
* jsc#MSQA-992
* jsc#PED-12918
## References:
* https://www.suse.com/security/cve/CVE-2023-45288.html
* https://www.suse.com/security/cve/CVE-2024-9264.html
* https://www.suse.com/security/cve/CVE-2024-9476.html
* https://www.suse.com/security/cve/CVE-2025-22870.html
* https://www.suse.com/security/cve/CVE-2025-22872.html
* https://www.suse.com/security/cve/CVE-2025-2703.html
* https://www.suse.com/security/cve/CVE-2025-29923.html
* https://www.suse.com/security/cve/CVE-2025-3454.html
* https://bugzilla.suse.com/show_bug.cgi?id=1231844
* https://bugzilla.suse.com/show_bug.cgi?id=1233343
* https://bugzilla.suse.com/show_bug.cgi?id=1236510
* https://bugzilla.suse.com/show_bug.cgi?id=1236516
* https://bugzilla.suse.com/show_bug.cgi?id=1238686
* https://bugzilla.suse.com/show_bug.cgi?id=1238703
* https://bugzilla.suse.com/show_bug.cgi?id=1241683
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.