This update for grafana fixes the following issues:
grafana was updated from version 9.5.18 to 10.4.13
(jsc#PED-11591,jsc#PED-11649):
* Security issues fixed:
* CVE-2024-45337: Prevent possible misuse of ServerConfig.PublicKeyCallback by
upgrading golang.org/x/crypto (bsc#1234554)
* CVE-2023-3128: Fixed authentication bypass using Azure AD OAuth
(bsc#1212641)
* CVE-2023-6152: Add email verification when updating user email (bsc#1219912)
* CVE-2024-6837: Fixed potential data source permission escalation
(bsc#1236301)
* CVE-2024-8118: Fixed permission on external alerting rule write endpoint
(bsc#1231024)
* Potential breaking changes in version 10:
* In panels using the `extract fields` transformation, where one of the
extracted names collides with one of the already existing ields, the
extracted field will be renamed.
* For the existing backend mode users who have table visualization might see
some inconsistencies on their panels. We...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-545=1
* SUSE Package Hub 15 15-SP6
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-545=1
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* grafana-10.4.13-150200.3.59.1
* grafana-debuginfo-10.4.13-150200.3.59.1
* SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64)
* grafana-10.4.13-150200.3.59.1
* grafana-debuginfo-10.4.13-150200.3.59.1
* bsc#1212641
* bsc#1219912
* bsc#1231024
* bsc#1234554
* bsc#1236301
* jsc#MSQA-914
* jsc#PED-11591
* jsc#PED-11649
## References:
* https://www.suse.com/security/cve/CVE-2023-3128.html
* https://www.suse.com/security/cve/CVE-2023-6152.html
* https://www.suse.com/security/cve/CVE-2024-45337.html
* https://www.suse.com/security/cve/CVE-2024-6837.html
* https://www.suse.com/security/cve/CVE-2024-8118.html
* https://bugzilla.suse.com/show_bug.cgi?id=1212641
* https://bugzilla.suse.com/show_bug.cgi?id=1219912
* https://bugzilla.suse.com/show_bug.cgi?id=1231024
* https://bugzilla.suse.com/show_bug.cgi?id=1234554
* https://bugzilla.suse.com/show_bug.cgi?id=1236301
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role=
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11591&page_caps=&user_role=
* https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11649&page_caps=&user_role=
Get the latest Linux and open source security news straight to your inbox.